CVE-2025-15602: Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation
Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 8.3.7 - Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.3.7
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15602?
CVE-2025-15602 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-15602?
To fix CVE-2025-15602, you should upgrade Snipe-IT to version 8.3.7 or later.
What does CVE-2025-15602 exploit?
CVE-2025-15602 exploits insufficient protections against mass assignment of sensitive user attributes in Snipe-IT.
Who is affected by CVE-2025-15602?
Authenticated users with low privileges in Snipe-IT versions prior to 8.3.7 are affected by CVE-2025-15602.
What can occur if CVE-2025-15602 is exploited?
Exploitation of CVE-2025-15602 can lead to unauthorized privilege escalation, allowing low-privileged users to gain elevated access.