Impact
The vulnerability arises because Snipe‑IT versions prior to 8.7.0 do not validate the success of file writes when storing acceptance evidence. If the storage backend silently fails, the application proceeds to mark the acceptance as completed. This produces a record indicating completion, but the signature and acceptance PDF files are absent, leading to a material deficiency in compliance artifacts for EULA acknowledgement or equipment‑receipt processes.
Affected Systems
Affected versions are 8.6.3 and earlier of the Snipe‑IT application provided by grokability. The vulnerability exists in the AcceptanceController::store() path of the product, and the fix is included in the 8.7.0 release.
Risk and Exploitability
The CVSS score is 2.3, and the EPSS score is not available, indicating a low severity and uncertain exploitation likelihood. The vulnerability does not allow remote code execution or privilege escalation. The primary risk appears when the storage backend is misconfigured or exhausted; attackers cannot directly induce the silent failure. Consequently, the risk to confidentiality or high‑profile availability is minimal, but the integrity of compliance reporting is compromised.
OpenCVE Enrichment