Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
                
            References
                    | Link | Resource | 
|---|---|
| https://census-labs.com/news/2022/12/23/multiple-vulnerabilities-in-snipe-it/ | Exploit Third Party Advisory | 
| https://census-labs.com/news/2022/12/23/multiple-vulnerabilities-in-snipe-it/ | Exploit Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2022-12-25 05:15
Updated : 2025-04-15 14:15
NVD link : CVE-2022-44381
Mitre link : CVE-2022-44381
CVE.ORG link : CVE-2022-44381
JSON object : View
Products Affected
                snipeitapp
- snipe-it
CWE
                
                    
                        
                        CWE-203
                        
            Observable Discrepancy
