CVE-2024-48987

CVSS 3.1 Score 6.6 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Jan 7, 2025

Summary

CVE-2024-48987 is a remote code execution vulnerability affecting Snipe-IT before version 7.0.10. An attacker can exploit this issue by taking advantage of cookie serialization, requiring knowledge of the APP_KEY. The severity of this vulnerability is heightened due to the presence of default APP_KEY values found in .env files, publicly available in the product's repository. This flaw allows unauthorized users to execute arbitrary code on vulnerable instances of Snipe-IT.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share