VYPR

Teampass

by Nilsteampassnet

Source repositories

CVEs (50)

  • CVE-2017-15052MedNov 27, 2017
    risk 0.25cvss 4.9epss 0.01

    TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the…

  • CVE-2023-3190MedJun 10, 2023
    risk 0.23cvss 4.6epss 0.01

    Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2024-50701MedDec 30, 2024
    risk 0.21cvss 4.3epss 0.00

    TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin.

  • CVE-2012-2234Apr 22, 2012
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the login parameter in an add_new_user action.

  • CVE-2020-12479HigApr 29, 2020
    risk 0.00cvss 8.8epss 0.03

    TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.

  • CVE-2019-17205MedOct 5, 2019
    risk 0.00cvss 6.1epss 0.01

    TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

  • CVE-2014-3774Aug 7, 2014
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in items.php in TeamPass before 2.1.20 allow remote attackers to inject arbitrary web script or HTML via the group parameter, which is not properly handled in a (1) hid_cat or (2) open_folder form element, or (3) id parameter,…

  • CVE-2014-3773Aug 7, 2014
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL commands via the login parameter in a (1) send_pw_by_email or (2) generate_new_password action in sources/main.queries.php; iDisplayStart parameter to (3)…

  • CVE-2014-3772Aug 7, 2014
    risk 0.00cvss epss 0.03

    TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that calls the session_start function before checking the CPM key, as demonstrated by a request to sources/upload/upload.files.php.

  • CVE-2014-3771Aug 7, 2014
    risk 0.00cvss epss 0.03

    TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2) "change_user_language" request to sources/main.queries.php.

Page 3 of 3