CVE-2024-5685 is a critical access control vulnerability affecting Snipe-IT versions 4.6.17 through 6.4.1. It allows authenticated users with "User:edit" and "Self:api" permissions to elevate or demote their own or other users' privileges by manipulating group memberships via API calls. With a CVSS score of 8.1 (High), this vulnerability presents a low-complexity attack vector that can lead to significant confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.6.17, < 6.4.2CPE matchmatch criteria | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | ||
>= v4.6.17, <= v6.4.1CPE match | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.