snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/a2fac2eb-100d-45b1-9ac7-71847c2f2b6b | exploit third party advisory patch |
https://github.com/snipe/snipe-it/commit/84c73aae5dcafa9529ceeeda6e8cdda5a42129c3 | third party advisory patch |