CVE Vulnerabilities

CVE-2014-3772

Published: Aug 07, 2014 | Modified: Aug 07, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that calls the session_start function before checking the CPM key, as demonstrated by a request to sources/upload/upload.files.php.

Affected Software

Name Vendor Start Version End Version
Teampass Teampass * 2.1.20 (including)
Teampass Teampass 2.1 (including) 2.1 (including)
Teampass Teampass 2.1.1 (including) 2.1.1 (including)
Teampass Teampass 2.1.2 (including) 2.1.2 (including)
Teampass Teampass 2.1.3 (including) 2.1.3 (including)
Teampass Teampass 2.1.4 (including) 2.1.4 (including)
Teampass Teampass 2.1.5 (including) 2.1.5 (including)
Teampass Teampass 2.1.10 (including) 2.1.10 (including)
Teampass Teampass 2.1.13 (including) 2.1.13 (including)
Teampass Teampass 2.1.14 (including) 2.1.14 (including)
Teampass Teampass 2.1.15 (including) 2.1.15 (including)
Teampass Teampass 2.1.18 (including) 2.1.18 (including)
Teampass Teampass 2.1.19 (including) 2.1.19 (including)

References