Impact
Snipe‑IT, an IT asset and license management platform, contains an IDOR flaw that lets an authenticated user with generic asset edit permissions delete files attached to assets outside the user’s ownership or company assignment. The issue originates from the destroy() methods in both the API and web controllers authorizing updates at the class level instead of the specific file instance, allowing any attachment to be removed. The flaw was fixed in version 8.4.1, but any deployment using earlier 8.x releases remains vulnerable.
Affected Systems
The flaw affects all Snipe‑IT deployments using version 8.x prior to 8.4.1. Any installation before the 8.4.1 release is vulnerable; the issue was fixed in that update.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is considered moderate, and it is not currently listed in CISA’s KEV catalog. The EPSS score is not available. Exploitation requires the attacker to be authenticated and to possess at least generic asset edit rights, a permission commonly granted to many users. Because the attack vector is confined to legitimate user credentials, the risk is limited to accounts that have been compromised or are subject to excessive permissions. No publicly known exploits exist as of now.
OpenCVE Enrichment
Github GHSA