Improper Access Control in snipe/snipe-it
Valid
Reported on
Feb 23rd 2022
Description
It was found that if a user is not having access to the requested items module, a normal user with no access can still access and view the requested content.
It is a more detailed explanation of the given report where it was marked as invalid : https://huntr.dev/bounties/783cfb0c-7e4d-4fdd-86c6-bd92743aee41/
Proof of Concept
- Create two users, one admin and one normal user(Only give view accessories access to the normal user)
- In the screenshot, you can see the normal user is not having access to the requested module.
- But with forced browsing, we can clearly see that the normal user can access the requested module.
Screenshots
Accessories view permission to normal user
Normal user view requested items
Impact
This vulnerability will help an attacker view restricted content.
We are processing your report and will contact the
snipe/snipe-it
team within 24 hours.
a year ago
shubh123-tri modified the report
a year ago
shubh123-tri modified the report
a year ago
We have contacted a member of the
snipe/snipe-it
team and are waiting to hear back
a year ago
We have sent a
follow up to the
snipe/snipe-it
team.
We will try again in 7 days.
a year ago
We have sent a
second
follow up to the
snipe/snipe-it
team.
We will try again in 10 days.
a year ago
We have sent a
third and final
follow up to the
snipe/snipe-it
team.
This report is now considered stale.
a year ago
The researcher's credibility has increased: +7
to join this conversation