Snipe-IT 是一款 IT 资产/许可管理系统。在版本 8.7.0 之前,具有 self.api 权限的账户在尚未完成第二因素认证挑战的情况下,其通过密码验证建立的会话仍可访问 personal-access-token API 流程。这是因为 CheckForTwoFactor 中间件仅在 Web 中间件组中生效,而在 API 中间件组中未生效。 根据安全通告,由此产生的持久性 API 令牌能够以受害者的权限读取和修改资源;对于管理员账户,该令牌还可访问 users/two_factor_reset 端点。重
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | < 8.7.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | < 8.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63498 | 8.7 HIGH | Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API |
| CVE-2026-62368 | 8.1 HIGH | Snipe-IT: Stored XSS via Custom Field name in asset-list column headers |
No comments yet