Vulnerabilities > CVE-2024-5685 - Unspecified vulnerability in Snipeitapp Snipe-It

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
snipeitapp

Summary

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

Vulnerable Configurations

Part Description Count
Application
Snipeitapp
87