CVE-2024-5685: Snipeitapp Snipe-It
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
Affected products
- Snipeitapp Snipe-It: from 4.6.17, before 6.4.2 (fixed in 6.4.2)
Published 2024-06-14. Last modified 2026-06-17.