Impact
Snipe-IT, an IT asset and license management application, contains a path‑traversal flaw in its CSV import routine. An attacker who can authenticate to the system and holds the import and assets.update permissions can embed a traversal sequence in the image field of a CSV record. When the system subsequently deletes the referenced image, the path is resolved against the underlying file system, permitting removal of any file reachable by the server process. This results in loss of data and can disrupt services that rely on the deleted assets. The weakness is classified as CWE‑22 and carries a CVSS score of 6.5.
Affected Systems
The flaw exists in all Snipe-IT releases earlier than version 8.6.2. Versions 8.6.2 and later include the fix and are not affected.
Risk and Exploitability
The CVSS score denotes moderate severity. An EPSS value of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The attacker must already have authenticated access with import and assets.update rights, so the threat primarily comes from insiders or compromised legitimate users. Once those privileges are in place, the attacker can delete any file that the server user can access.
OpenCVE Enrichment