VDB
KO
MEDIUM 5.8

GHSA-6x4j-8954-5hxm

Snipe-IT has a 2FA reset privilege bypass

Details

### Impact A user who can edit other users could reset a superadmin's 2FA.

### Patches Patched in 8.5.0

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / snipe/snipe-it
Introduced in: 0 Fixed in: 8.5.0
Fix composer require snipe/snipe-it:^8.5.0

References