Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://github.com/grokability/snipe-it/pull/16672 | issue tracking |
https://github.com/grokability/snipe-it/compare/v8.0.4...v8.1.0 | product |
https://github.com/grokability/snipe-it/releases/tag/v8.1.0 | release notes patch |
https://github.com/koyomihack00/CVE-2025-47226/blob/main/PoC/idor-exploit.md | patch exploit third party advisory |