CVE-2024-48987
CVSS 3.1 Score 6.6 of 10 (medium)
Details
Published Oct 11, 2024
Updated: Jan 7, 2025
Summary
CVE-2024-48987 is a remote code execution vulnerability affecting Snipe-IT before version 7.0.10. An attacker can exploit this issue by taking advantage of cookie serialization, requiring knowledge of the APP_KEY. The severity of this vulnerability is heightened due to the presence of default APP_KEY values found in .env files, publicly available in the product's repository. This flaw allows unauthorized users to execute arbitrary code on vulnerable instances of Snipe-IT.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.