VDB
Sign up
0.0

GHSA-xr9m-gphc-9p63

Snipe-IT has a path traversal vulnerability via CSV import `image` field

Quick fix

GHSA-xr9m-gphc-9p63 — snipe/snipe-it: upgrade to the fixed version with the command below.

composer require snipe/snipe-it:^8.6.2

Details

### Impact An authenticated user holding the `import` and `assets.update` permissions can delete arbitrary files on the server filesystem by injecting a path traversal string into an asset's `image` field via CSV import, then triggering the image deletion feature.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/snipe/snipe-it
Introduced in: 0Fixed in: 8.6.2
Fixcomposer require snipe/snipe-it:^8.6.2

References