Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5448-v74m-7mv7 | Snipe-IT has sensitive user attributes related to account privileges that are insufficiently protected against mass assignment |
Fri, 17 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Snipeitapp
Snipeitapp snipe-it |
|
| CPEs | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Snipeitapp
Snipeitapp snipe-it |
Mon, 09 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grokability, Inc.
Grokability, Inc. snipe-it |
|
| Vendors & Products |
Grokability, Inc.
Grokability, Inc. snipe-it |
Fri, 06 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance. | |
| Title | Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation | |
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-09T15:12:11.595Z
Reserved: 2026-03-06T16:13:18.460Z
Link: CVE-2025-15602
Updated: 2026-03-09T15:12:08.232Z
Status : Analyzed
Published: 2026-03-06T17:16:24.600
Modified: 2026-04-17T21:30:32.877
Link: CVE-2025-15602
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:07:20Z
Github GHSA