Access Control Flaw in TeamPass Information Management Software
CVE-2017-15052
4.9MEDIUM
What is CVE-2017-15052?
TeamPass versions before 2.1.27.9 exhibit a significant access control vulnerability which allows users with manager privileges to delete or modify arbitrary user accounts. This exploitation occurs via tampering with request parameters sent to the users.queries.php endpoint, enabling an authenticated attacker to alter user attributes or remove any user, including administrative accounts, posing a threat to overall system integrity.
