Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.
References
Configurations
History
No history.
Information
Published : 2025-11-05 16:15
Updated : 2025-12-01 16:15
NVD link : CVE-2025-63601
Mitre link : CVE-2025-63601
CVE.ORG link : CVE-2025-63601
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
