CyberRota Analysis
AI-GeneratedSnipe-IT versions prior to 8.7.0 are vulnerable to a flaw in the restore endpoint that allows superusers to inadvertently wipe the database by uploading corrupted or invalid backup archives. This results in permanent data loss without any recovery options, making it critical for organizations using affected versions to prioritize upgrading to mitigate this risk. Superusers and database administrators should be particularly vigilant in addressing this vulnerability to prevent catastrophic data loss.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Related CVEs
Other vulnerabilities affecting the same vendor(s)