CVE-2025-59713
BaseFortify
Publication date: 2025-09-19
Last updated on: 2025-09-23
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| snipeitapp | snipe-it | to 8.1.18 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Snipe-IT versions before 8.1.18 involves unsafe deserialization, which means that the software improperly processes serialized data. This can allow an attacker to manipulate the data to execute malicious code or actions within the application.
How can this vulnerability impact me? :
The impact of this vulnerability includes potential unauthorized code execution and compromise of confidentiality and integrity of data within the affected Snipe-IT application. According to the CVSS score, it has a high impact on confidentiality and integrity but does not affect availability.