In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade snipe/snipe-it to version 8.4.1 or higher.
snipe/snipe-it is an asset management system built on Laravel.
Affected versions of this package are vulnerable to Incorrect Authorization in the PATCH process to /api/v1/users/{id} when the permissions array is not properly restricted. An attacker can gain unauthorized administrative privileges by assigning themselves the admin permission through crafted API requests.