Impact
Snipe-IT versions prior to 8.7.0 do not HTML-escape the employee_num field when generating acceptance PDFs, allowing attackers with users.edit permission to inject arbitrary <img> tags into TCPDF's writeHTML() function; the embedded image URL causes the server to issue a request to that address, resulting in server‑side request forgery. This flaw enables attackers to direct the application to connect to internal network services, cloud metadata endpoints, or external targets, potentially exposing sensitive data or facilitating further lateral movement. The impact is primarily a confidentiality breach through internal request redirection, with limited availability effects and no direct code execution.
Affected Systems
The affected product is Snipe‑IT, provided by Grokability. All releases before 8.7.0 are vulnerable, regardless of the operating system or deployment environment.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.3, indicating high severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but its exploitation requires only user-level edit rights and the ability to trigger asset acceptance, both of which are common administrative tasks. Attackers can exploit the flaw by injecting a crafted employee_num value containing an <img> tag with an arbitrary HTTP(S) URL, resulting in the Snipe‑IT server making unauthorized outbound requests. Because the vulnerability leverages existing PDF rendering code, it can be abused with minimal effort once the edit permission context is obtained.
OpenCVE Enrichment