Observable Response Discrepancy in snipe-it - #VU145098
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to observable response discrepancy in Api\\LicensesController::index() when processing product_key, filter, or search queries against license serial values. A remote user can submit crafted API queries to disclose sensitive information.
The response masks the product key value, but the total count and presence or absence of rows reveal whether a candidate key or substring matched.