snipeitapp
3 records · 3 with a public proof-of-concept
Disclosed vulnerabilities where the NVD names snipeitapp as an affected vendor, highest CVSS first.
- HIGH 8.7CVE-2026-63498public PoC
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with …
snipe-it
- HIGH 8.1CVE-2026-63493public PoC
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwo…
snipe-it
- HIGH 8.1CVE-2026-62368public PoC
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When …
snipe-it