CyberRota Analysis
AI-GeneratedVersions of Snipe-IT prior to 8.7.0 are vulnerable due to an improper ownership management flaw in the consumables checkout API, allowing authenticated users with checkout permissions to misattribute audit trail entries. This can lead to confusion regarding which operator performed specific actions, potentially undermining accountability and traceability in asset management. Organizations using affected versions should prioritize updating to mitigate the risk of unauthorized actions being obscured in their audit logs.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.