corentin-soriano

2 exploits Active since Dec 2024
CVE-2024-50702 WRITEUP MEDIUM WRITEUP
TeamPass < 3.1.3.1 - Incorrect Privilege Assignment in Mail Action
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.
CVSS 5.4
CVE-2024-50703 WRITEUP MEDIUM WRITEUP
TeamPass <3.1.3.1 - Privilege Escalation
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
CVSS 5.4