CVE-2024-48987
MEDIUMDescription
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.
Is your site exposed to CVE-2024-48987?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| snipeitapp | snipe-it |
References
Frequently Asked Questions
What is CVE-2024-48987? +
How severe is CVE-2024-48987? +
What products are affected by CVE-2024-48987? +
How do I check if I'm vulnerable to CVE-2024-48987? +
Related Vulnerabilities
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username …
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` …
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH …
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require …
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build …
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal …