CVE-2025-47226
02.05.2025, 21:15
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
Vendor | Product | Version |
---|---|---|
snipeitapp | snipe-it | 𝑥 < 8.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-425 - Direct Request ('Forced Browsing')The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.