Impact
This vulnerability allows any authenticated user to use the POST /hardware/history endpoint to reassign assets and modify audit logs without proper authorization checks. By submitting a specially crafted CSV file, an attacker can reassign assets to other companies and inject fraudulent audit trail entries, eroding inventory integrity and accountability.
Affected Systems
The affected product is Snipe‑IT, a web‑based asset management application from the vendor Snipe‑IT. All releases before 8.7.0 are susceptible; versions 8.7.0 and later include the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for this missing authorization flaw. EPSS for this vulnerability is not available, and it is not listed in the CISA KEV catalog, yet the potential impact on inventory accountability is severe. Based on the description, the likely attack vector is an authenticated user exploiting the CSV importer endpoint; an attacker must first have valid credentials to use the interface.
OpenCVE Enrichment