VYPR

Teampass

by Nilsteampassnet

Source repositories

CVEs (50)

  • CVE-2019-1000001CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.02

    TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass…

  • CVE-2017-9436CriJun 5, 2017
    risk 0.64cvss 9.8epss 0.01

    TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.

  • CVE-2015-7564CriApr 12, 2017
    risk 0.60cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b)…

  • CVE-2020-12479HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.03

    TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.

  • CVE-2020-11671HigMay 4, 2020
    risk 0.53cvss 8.1epss 0.01

    Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by…

  • CVE-2015-7563HigApr 12, 2017
    risk 0.53cvss 8.8epss 0.03

    Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.

  • CVE-2023-3086CriJun 3, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-3083HigJun 3, 2023
    risk 0.50cvss 8.7epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-2859HigMay 24, 2023
    risk 0.50cvss 8.8epss 0.02

    Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2020-12478HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.09

    TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

  • CVE-2020-12477HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.02

    The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.

  • CVE-2023-3084HigJun 3, 2023
    risk 0.46cvss 8.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2017-15055HigNov 27, 2017
    risk 0.46cvss 8.1epss 0.01

    TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the…

  • CVE-2023-1545HigMar 21, 2023
    risk 0.45cvss 7.5epss 0.08

    SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

  • CVE-2023-3553HigJul 8, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2017-15054HigNov 27, 2017
    risk 0.42cvss 7.5epss 0.04

    An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to…

  • CVE-2023-3551HigJul 8, 2023
    risk 0.40cvss 7.2epss 0.01

    Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2022-26980MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.

  • CVE-2019-17205MedOct 5, 2019
    risk 0.40cvss 6.1epss 0.01

    TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

  • CVE-2023-1070HigFeb 27, 2023
    risk 0.39cvss 7.1epss 0.01

    External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

Page 1 of 3