Impact
The flaw lies in an incorrect calculation of the assets.requests_counter during checkout request processing. Authenticated users can submit duplicate checkout requests or repeatedly call the cancel endpoint when no active request exists. These actions allow the counter to be forcefully increased or driven into negative values, distorting the inventory‑management snapshot presented to administrators. The result is a credible integrity issue that can mislead resource planning and reporting operations.
Affected Systems
All installations of snipe‑it prior to version 8.7.0 are vulnerable, including any releases in the 8.x series that fall before the stated cutoff. The product, developed by grokability and identified by the CPE snipeitapp:snipe‑it, is affected for every user who can authenticate to the API or web interface.
Risk and Exploitability
The vulnerability receives a moderate CVSS score of 5.3. Its EPSS score is not available and it is not listed in the CISA KEV catalog, indicating no widespread exploitation data yet. The attack requires legitimate authentication; the exploit path is straightforward—submit duplicate checkout or cancel requests via the exposed endpoints. Even though the potential damage is limited to inventory count corruption, it can create operational disruptions or financial inaccuracies if left unmitigated.
OpenCVE Enrichment