TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2) change_user_language request to sources/main.queries.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Teampass | Teampass | * | 2.1.20 (including) |
Teampass | Teampass | 2.1 (including) | 2.1 (including) |
Teampass | Teampass | 2.1.1 (including) | 2.1.1 (including) |
Teampass | Teampass | 2.1.2 (including) | 2.1.2 (including) |
Teampass | Teampass | 2.1.3 (including) | 2.1.3 (including) |
Teampass | Teampass | 2.1.4 (including) | 2.1.4 (including) |
Teampass | Teampass | 2.1.5 (including) | 2.1.5 (including) |
Teampass | Teampass | 2.1.10 (including) | 2.1.10 (including) |
Teampass | Teampass | 2.1.13 (including) | 2.1.13 (including) |
Teampass | Teampass | 2.1.14 (including) | 2.1.14 (including) |
Teampass | Teampass | 2.1.15 (including) | 2.1.15 (including) |
Teampass | Teampass | 2.1.18 (including) | 2.1.18 (including) |
Teampass | Teampass | 2.1.19 (including) | 2.1.19 (including) |