Lucene search

K
cve[email protected]CVE-2014-3772
HistoryAug 07, 2014 - 11:13 a.m.

CVE-2014-3772

2014-08-0711:13:35
CWE-264
web.nvd.nist.gov
23
nvd
cve-2014-3772
teampass
security
access restrictions
remote attackers

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.7%

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that calls the session_start function before checking the CPM key, as demonstrated by a request to sources/upload/upload.files.php.

Affected configurations

NVD
Node
teampassteampassRange2.1.20beta
OR
teampassteampassMatch2.1
OR
teampassteampassMatch2.1.1
OR
teampassteampassMatch2.1.2
OR
teampassteampassMatch2.1.3
OR
teampassteampassMatch2.1.4
OR
teampassteampassMatch2.1.5
OR
teampassteampassMatch2.1.10
OR
teampassteampassMatch2.1.13
OR
teampassteampassMatch2.1.14
OR
teampassteampassMatch2.1.15
OR
teampassteampassMatch2.1.18
OR
teampassteampassMatch2.1.19

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.7%

Related for CVE-2014-3772