vendor:
Snipe-IT
by:
Sn1p3r-H4ck3r (Siripong Jintung)
6.1
CVSS
HIGH
Insecure Direct Object Reference (IDOR)
285
CWE
Product Name: Snipe-IT
Affected Version From: 8.0.4
Affected Version To: 8.0.4
Patch Exists: YES
Related CWE: CVE-2025-47226
CPE: a:grokability:snipe-it:8.0.4
Platforms Tested: Ubuntu 22.04 LTS, Apache2 + MySQL + PHP 8.1
2025
Grokability Snipe-IT 8.0.4 Insecure Direct Object Reference (IDOR) Vulnerability
Snipe-IT version 8.0.4 and below has an IDOR vulnerability in the `/locations/<id>/printassigned` endpoint. This allows an authenticated user to access asset assignment data of other departments by changing the `location_id` in the URL.
Mitigation:
Upgrade to Snipe-IT version 8.1.0 or later to fix the access control validation.