PT-2026-23723 · Snipe-It · Snipe-It
Luca D
+1
·
Published
2026-03-06
·
Updated
2026-03-07
·
CVE-2025-15602
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.3.7
Description
Snipe-IT instances running versions prior to 8.3.7 are susceptible to unauthorized modification of user account details due to insufficient protection of sensitive user attributes against mass assignment. An authenticated user with low privileges can construct a malicious API request to alter restricted fields of other user accounts, including the Super Admin account. Specifically, an attacker can change the email address associated with the Super Admin account and initiate a password reset, leading to full administrative control of the Snipe-IT instance. The vulnerable API allows modification of user attributes through a mass assignment flaw. The
email attribute is particularly susceptible to this manipulation.Recommendations
Update Snipe-IT to version 8.3.7 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It