Impact
Snipe‑IT versions prior to 8.7.0 generate the unaccepted assets acceptance report CSV without escaping spreadsheet formula characters. An authenticated user with basic create/edit rights can set a free‑text field (such as asset name, company name, category, model, or assignee display name) to a value that starts with a formula indicator such as =, +, -, @, a tab, or a carriage return. When a user with reports.view privileges exports the report and the recipient opens the CSV in Excel, LibreOffice Calc or Google Sheets, the injected content is interpreted as a spreadsheet formula, enabling the attacker to exfiltrate data or, on legacy Windows Excel configurations, trigger DDE command execution.
Affected Systems
Snipe‑IT installations on web servers running the application, specifically versions up to and including 8.6.3. The vulnerability exists in the POST /reports/unaccepted_assets endpoint, which produces the CSV file that is transmitted to users.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate overall risk. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with both record‑edit and reports.view privileges. It then depends on the victim opening the exported CSV in a spreadsheet application. The impact is data exfiltration via spreadsheet formulas or, in some legacy configurations, client‑side code execution. Because the attack vector relies on user interaction, the overall risk is moderate unless the spreadsheet export is frequently processed by users.
OpenCVE Enrichment