snipe-it is vulnerable to Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://huntr.dev/bounties/19453ef1-4d77-4cff-b7e8-1bc8f3af0862 | issue tracking patch exploit third party advisory |
https://github.com/snipe/snipe-it/commit/1699c09758e56f740437674a8d6ba36443399f24 | third party advisory patch |