Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
References
Link | Resource |
---|---|
https://github.com/grokability/snipe-it/compare/v8.0.4...v8.1.0 | Product |
https://github.com/grokability/snipe-it/pull/16672 | Issue Tracking |
https://github.com/grokability/snipe-it/releases/tag/v8.1.0 | Release Notes Patch |
https://github.com/koyomihack00/CVE-2025-47226/blob/main/PoC/idor-exploit.md | Exploit Patch Third Party Advisory |
Configurations
History
03 Jun 2025, 14:44
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-639 | |
CPE | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
First Time |
Snipeitapp snipe-it
Snipeitapp |
|
References | () https://github.com/grokability/snipe-it/compare/v8.0.4...v8.1.0 - Product | |
References | () https://github.com/grokability/snipe-it/pull/16672 - Issue Tracking | |
References | () https://github.com/grokability/snipe-it/releases/tag/v8.1.0 - Release Notes, Patch | |
References | () https://github.com/koyomihack00/CVE-2025-47226/blob/main/PoC/idor-exploit.md - Exploit, Patch, Third Party Advisory |
05 May 2025, 20:54
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 May 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-02 21:15
Updated : 2025-06-03 14:44
NVD link : CVE-2025-47226
Mitre link : CVE-2025-47226
CVE.ORG link : CVE-2025-47226
JSON object : View
Products Affected
snipeitapp
- snipe-it