CVE-2022-0178

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to access and manipulate data in the Snipe-IT application without proper authorization, potentially leading to unauthorized changes or data exposure. It affects versions before 5.3.8, so users running older versions are at risk if they haven't updated.

Technical Description

Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$741($500-$1K)
Vendor Response
Grade FPatched in 1502 days

Quick Information

Published

Jan 13, 2022

about 4 years ago

Last Modified

Feb 24, 2026

about 1 month ago

Vendor

snipeitapp

Product

snipe-it