TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a users allowed folders list that has been defined by an admin.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.