Vulnerabilities
Vulnerable Software
Snipeitapp:  >> Snipe-It  >> 8.4.0  Security Vulnerabilities
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.
CVSS Score
5.9
EPSS Score
0.002
Published
2026-05-26
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
CVSS Score
9.8
EPSS Score
0.006
Published
2026-05-07
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-04-14


Contact Us

Shodan ® - All rights reserved