7.5

CVE-2014-3772

Exploit
TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that calls the session_start function before checking the CPM key, as demonstrated by a request to sources/upload/upload.files.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TeampassTeampass Updatebeta Version <= 2.1.20
TeampassTeampass Version2.1
TeampassTeampass Version2.1.1
TeampassTeampass Version2.1.2
TeampassTeampass Version2.1.3
TeampassTeampass Version2.1.4
TeampassTeampass Version2.1.5
TeampassTeampass Version2.1.10
TeampassTeampass Version2.1.13
TeampassTeampass Version2.1.14
TeampassTeampass Version2.1.15
TeampassTeampass Version2.1.18
TeampassTeampass Version2.1.19
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.65% 0.836
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://teampass.net/installation/2.1.20-released.html
Vendor Advisory
http://www.openwall.com/lists/oss-security/2014/05/18/2
http://www.openwall.com/lists/oss-security/2014/05/19/5
https://github.com/nilsteampassnet/TeamPass/commit/7715512f2bd5659cc69e063a1c513c19e384340f
Patch
Exploit