IP Whitelisting Bypass in TeamPass by Teampass Net
CVE-2020-12477
7.5HIGH
What is CVE-2020-12477?
The REST API functions in TeamPass prior to version 2.1.27.36 contain a vulnerability that allows users with a valid API token to bypass IP address whitelist protections. This exploit leverages the X-Forwarded-For HTTP header to manipulate the getIp function, potentially granting unauthorized access to sensitive data without proper restrictions.
