CyberRota Analysis
AI-GeneratedThe Importer API endpoint in Snipe-IT prior to version 8.6.1 is vulnerable, allowing users with CSV import capabilities and a valid API key to unauthorizedly modify the ownership metadata of import files. This could lead to incorrect attribution of asset ownership, potentially compromising asset management integrity. Organizations using Snipe-IT should prioritize upgrading to version 8.6.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)