InvenTree
cpe:2.3:a:inventree_project:inventree:*:*:*:*:*:*:*
- >= 0.16.0, < 1.2.7
A vulnerability in InvenTree, an open-source inventory management system, allows authenticated users to create API tokens for any other user, including administrators and superusers. This is achieved by sending the target user's ID in the user field of a POST request to /api/user/tokens/. The generated token can be used immediately for full API authentication as the targeted user, from any network location, without any additional interaction.
Exploitation of this vulnerability allows for unauthorized API access as another user, potentially leading to unauthorized actions or data access, especially if the impersonated user has elevated privileges.
Users can upgrade to InvenTree versions 1.2.7 or 1.3.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.