Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload…
Medium CVSS 6.3
Summary
Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only assets.files permission can mutate shared model file attachments across company boundaries and bypass the dedicated models.files permission intended to restrict file management on th…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/grokability/snipe-it/security/advisories/GHSA-rhrf-7x22-x2rj Exploit
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-broken-access-control-via-assetmodelpolicy Third Party Advisory
Timeline
- nvd_ingest NVD