Critical severity9.8NVD Advisory· Published Apr 12, 2017· Updated May 13, 2026
CVE-2015-7564
CVE-2015-7564
Description
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nilsteampassnet/teampassPackagist | < 2.1.25 | 2.1.25 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/nilsteampassnet/TeamPass/pull/1140nvdPatchWEB
- www.exploit-db.com/exploits/39559/nvdExploitPatchThird Party Advisory
- github.com/advisories/GHSA-r64j-5w3w-fp49ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-7564ghsaADVISORY
- www.exploit-db.com/exploits/39559ghsaWEB
News mentions
0No linked articles in our index yet.