Access Control Flaw in TeamPass Information Management Software
CVE-2017-15052

4.9MEDIUM

Key Information:

Vendor

Teampass

Status
Vendor
CVE Published:
27 November 2017

What is CVE-2017-15052?

TeamPass versions before 2.1.27.9 exhibit a significant access control vulnerability which allows users with manager privileges to delete or modify arbitrary user accounts. This exploitation occurs via tampering with request parameters sent to the users.queries.php endpoint, enabling an authenticated attacker to alter user attributes or remove any user, including administrative accounts, posing a threat to overall system integrity.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.