CVE-2024-5685
14.06.2024, 10:15
Users with "User:edit" and "Self:api" permissionscan promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.Enginsight
Vendor | Product | Version |
---|---|---|
snipeitapp | snipe-it | 4.6.17 ≤ 𝑥 < 6.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References