Lucene search

K
cve[email protected]CVE-2014-3771
HistoryAug 07, 2014 - 11:13 a.m.

CVE-2014-3771

2014-08-0711:13:35
CWE-264
web.nvd.nist.gov
19
cve-2014-3771
teampass
access restrictions
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.7%

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2) “change_user_language” request to sources/main.queries.php.

Affected configurations

NVD
Node
teampassteampassRange2.1.20beta
OR
teampassteampassMatch2.1
OR
teampassteampassMatch2.1.1
OR
teampassteampassMatch2.1.2
OR
teampassteampassMatch2.1.3
OR
teampassteampassMatch2.1.4
OR
teampassteampassMatch2.1.5
OR
teampassteampassMatch2.1.10
OR
teampassteampassMatch2.1.13
OR
teampassteampassMatch2.1.14
OR
teampassteampassMatch2.1.15
OR
teampassteampassMatch2.1.18
OR
teampassteampassMatch2.1.19

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.7%

Related for CVE-2014-3771