Impact
Prior to version 8.7.0, the Snipe‑IT application does not sanitize the EULA text field for category settings. A user with low‑privilege rights can inject markdown image syntax or raw HTML image tags that reference local files or remote URLs. When the application generates a checkout confirmation email, its auto‑embed library resolves those references server‑side and attaches the referenced content to the email before sending. This allows the attacker to read sensitive files such as .env credentials from the server’s filesystem and to direct the mail system to fetch arbitrary external resources, effectively enabling server‑side request forgery (SSRF).
Affected Systems
The vulnerability exists in the Snipe‑IT web application released by grokability. All releases prior to 8.7.0 contain the unfiltered EULA processing code and are therefore susceptible.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. Although the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog, its exploitation requires only low‑privilege access and allows the exfiltration of confidential files via outbound email attachments. The risk is significant for deployments where users receive these emails or where local email servers are used, as attackers could read sensitive secrets or perform SSRF attacks without additional privileges.
OpenCVE Enrichment