Lucene search

K
huntrHaxatronEFDF2EAD-F9D1-4767-9F02-D11F762D15E7
HistoryJan 06, 2022 - 1:16 a.m.

Improper Access Control in snipe/snipe-it

2022-01-0601:16:06
haxatron
www.huntr.dev
6

0.001 Low

EPSS

Percentile

21.4%

Description

All bulk actions (bulk-edit / bulk-delete / form info) in asset models do not have access control checks

Proof of concept

1: Grant view to Asset Models

2: UI for bulk-edit and bulk-delete is still enabled, proceed.

3: You may bulk-delete / edit any asset model

Impact

This vulnerability is capable of viewing / editing / delete asset model information with DENY permissions,

0.001 Low

EPSS

Percentile

21.4%

Related for EFDF2EAD-F9D1-4767-9F02-D11F762D15E7