CVE-2022-0178
Medium
|5.4Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to access and manipulate data in the Snipe-IT application without proper authorization, potentially leading to unauthorized changes or data exposure. It affects versions before 5.3.8, so users running older versions are at risk if they haven't updated.
Technical Description
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactNone
ScopeUnchanged
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$741($500-$1K)
Vendor Response
Grade FPatched in 1502 days
Quick Information
Published
Jan 13, 2022
about 4 years ago
Last Modified
Feb 24, 2026
about 1 month ago
Vendor
snipeitapp
Product
snipe-it