PHP File Inclusion Vulnerability in TeamPass by TeamPass Team
CVE-2020-12479
8.8HIGH
What is CVE-2020-12479?
TeamPass 2.1.27.36 contains a vulnerability that allows authenticated users to exploit a PHP file inclusion issue. This vulnerability can be triggered through a specially crafted HTTP request targeting the sources/users.queries.php file, resulting in potential directory traversal attacks. It is crucial for users to assess their security posture and apply appropriate mitigations to safeguard their installations.
