Impact
Snipe‑IT versions 8.6.3 and earlier delete the current image file without verifying that the new file was successfully written, and then overwrite the database reference with the new filename. This unchecked return value flaw causes the original image to be permanently removed while the database points to a non‑existent file, resulting in irrecoverable data loss for every picture stored in the application.
Affected Systems
All Snipe‑IT installations running version 8.6.3 or earlier are affected. Every model that can carry an image, including assets, asset models, users, companies, manufacturers, locations, categories, suppliers, and departments, routes through the vulnerable upload routine.
Risk and Exploitability
The flaw is triggered only when a legitimate, authenticated user submits an image upload and the underlying storage backend (S3, local filesystem, etc.) temporarily fails to write or delete the file. No remote attacker can directly trigger the flaw; however, an ordinary user or an automated scan could inadvertently cause data loss if the storage is misconfigured. The CVSS score of 7 indicates moderate severity. EPSS is not available, and the issue is not listed in CISA KEV, so the likelihood of widespread exploitation is low but the impact if triggered is significant.
OpenCVE Enrichment