Users with "User:edit" and... CVE-2024-5685

- AV AC AU C I A
发布: 2025-03-08
修订: 2025-03-08

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息