← Back

CVE-2014-3772

nvd nist
Published: Aug 7, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that calls the session_start function before checking the CPM key, as demonstrated by a request to sources/upload/upload.files.php.

Affected (13)

Products: Teampass: Teampass
1 product
Teampass
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Teampass
Up to 2.1.20
Version 2.1.10
Version 2.1.13
Version 2.1.14
Version 2.1.15
Version 2.1.18
Version 2.1.19
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1

Related CWEs

Timeline

No history available yet.