Tag
high
advisory
Pimcore WebDAV Asset MOVE Missing Authorization Vulnerability
2 rules 2 TTPsPimcore's WebDAV asset endpoint exposes a `MOVE` operation without authentication, allowing unauthenticated remote attackers to delete assets if they know two existing asset paths in the same directory; Authenticated low-privileged users may also be able to perform unauthorized asset move or overwrite operations because the move path does not enforce `rename`, `delete`, `create`, or `publish` permissions, leading to data loss, content integrity loss, and service disruption.
pimcore/pimcore
webdav
asset-management
missing-authorization
pimcore
2r
2t
critical
advisory
Snipe-IT File Upload Vulnerability Leads to Remote Code Execution (CVE-2026-37709)
2 rules 1 TTP 1 CVESnipe-IT versions prior to 8.4.1 are vulnerable to remote code execution due to insecure permissions on file uploads, where an attacker can upload arbitrary files and execute code on the server.
snipe-it
remote code execution
file upload
insecure permissions
asset management
CVE-2026-37709
2r
1t
1c