PT-2014-5489 · Teampass · Teampass

Matthew Daley

·

Publicado

2014-08-07

·

Atualizado

2014-08-07

·

CVE-2014-3772

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TeamPass versions prior to 2.1.20
Description The issue allows remote attackers to bypass access restrictions. This can be achieved by sending a request to "index.php" followed by a direct request to a file that calls the session start() function before checking the CPM key. An example of such a request is a call to "sources/upload/upload.files.php".
Recommendations For versions prior to 2.1.20, update to version 2.1.20 or later to resolve the issue. As a temporary workaround, consider restricting direct access to files that call the session start() function before verifying the CPM key.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3772

Produtos afetados

Teampass