Grokability Snipe-IT是Grokability公司开源的一套面向企业的IT资产与运维管理平台。 Grokability Snipe-IT 8.6.3之前版本存在授权问题漏洞,该漏洞源于批量删除功能存在授权绕过问题,允许受限用户软删除其授权范围之外的用户,攻击者可在批量删除请求中包含未授权用户ID,绕过实例级限制,修改或禁用不应访问的账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | < 8.6.3 |
affected |
8.6.3 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | 0 ~ 8.6.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet