Access Control Vulnerability in TeamPass by TeamPass
CVE-2017-15053

4.9MEDIUM

Key Information:

Vendor

Teampass

Status
Vendor
CVE Published:
27 November 2017

What is CVE-2017-15053?

An access control vulnerability exists in TeamPass prior to version 2.1.27.9, allowing users with manager rights to improperly manipulate user roles. This flaw can be exploited by an authenticated attacker who tampers with the application's requests, enabling them to delete or modify arbitrary roles without proper authorization. It's crucial for organizations utilizing TeamPass to update their installations to mitigate this risk.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.