PT-2026-23723 · Snipe-It · Snipe-It

Luca D

+1

·

Published

2026-03-06

·

Updated

2026-03-07

·

CVE-2025-15602

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.3.7
Description Snipe-IT instances running versions prior to 8.3.7 are susceptible to unauthorized modification of user account details due to insufficient protection of sensitive user attributes against mass assignment. An authenticated user with low privileges can construct a malicious API request to alter restricted fields of other user accounts, including the Super Admin account. Specifically, an attacker can change the email address associated with the Super Admin account and initiate a password reset, leading to full administrative control of the Snipe-IT instance. The vulnerable API allows modification of user attributes through a mass assignment flaw. The email attribute is particularly susceptible to this manipulation.
Recommendations Update Snipe-IT to version 8.3.7 or later.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-15602
GHSA-5448-V74M-7MV7

Affected Products

Snipe-It