Snipe-IT是Snipe-IT公司的一款资产管理系统。 Snipe-IT 8.6.0之前版本存在安全漏洞,该漏洞源于cancel_by_admin和requestingUser值从用户控制的URL路径段读取且未进行服务端授权检查,存在不安全的直接对象引用,可能导致低权限用户绕过请求所有权检查,取消其他用户的待处理借出请求,并可通过枚举连续整数标识取消所有待处理请求,破坏资产请求工作流。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grokability | Snipe-IT | < 8.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grokability | Snipe-IT | 0 ~ 8.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet