Packagist Package Vulnerabilities
Vulnerabilities associated with nilsteampassnet/teampass.
Packages
Clear package- moodle/moodle437 vulnerabilities
- magento/community-edition362 vulnerabilities
- typo3/cms188 vulnerabilities
- magento/project-community-edition161 vulnerabilities
- wwbn/avideo144 vulnerabilities
- pimcore/pimcore132 vulnerabilities
- craftcms/cms128 vulnerabilities
- typo3/cms-core127 vulnerabilities
- dolibarr/dolibarr126 vulnerabilities
- concrete5/concrete5119 vulnerabilities
- drupal/core109 vulnerabilities
- phpmyadmin/phpmyadmin107 vulnerabilities
- thorsten/phpmyfaq106 vulnerabilities
- microweber/microweber105 vulnerabilities
- librenms/librenms101 vulnerabilities
- symfony/symfony100 vulnerabilities
- silverstripe/framework90 vulnerabilities
- drupal/drupal81 vulnerabilities
- mantisbt/mantisbt74 vulnerabilities
- shopware/platform74 vulnerabilities
- getgrav/grav69 vulnerabilities
- shopware/core65 vulnerabilities
- snipe/snipe-it57 vulnerabilities
- baserproject/basercms56 vulnerabilities
- mautic/core56 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
TeamPass does not properly check whether a folder is in a user's allowed folders listTeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. | CVSS-v4.0 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
TeamPass privileges issueTeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. | CVSS-v4.0 | EPSS0.461% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
TeamPass mail_me operation authorization issueTeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. | CVSS-v4.0 | EPSS0.301% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-3565MEDIUM | Cross-site Scripting (XSS) - Generic in nilsteampassnet/teampassCross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. CWE-79Jul 8, 2023 | CVSS5.4v3.1 | EPSS0.625% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3553HIGH | Exposure of Sensitive Information to an Unauthorized Actor in nilsteampassnet/teampassExposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10. CWE-200Jul 8, 2023 | CVSS7.5v3.1 | EPSS0.828% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3552MEDIUM | Improper Encoding or Escaping of Output in nilsteampassnet/teampassImproper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. CWE-116Jul 8, 2023 | CVSS5.4v3.1 | EPSS0.541% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3551HIGH | Code Injection in nilsteampassnet/teampassCode Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. CWE-94Jul 8, 2023 | CVSS7.2v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3531MEDIUM | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. CWE-79Jul 6, 2023 | CVSS5.4v3.1 | EPSS0.537% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3190MEDIUM | Improper Encoding or Escaping of Output in nilsteampassnet/teampassImproper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-116Jun 10, 2023 | CVSS4.6v3.1 | EPSS0.522% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3191MEDIUM | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-79Jun 10, 2023 | CVSS5.4v3.1 | EPSS0.537% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3095MEDIUM | Improper Access Control in nilsteampassnet/teampassImproper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-284Jun 4, 2023 | CVSS6.5v3.1 | EPSS0.381% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3083HIGH | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-79Jun 3, 2023 | CVSS8.7v3.1 | EPSS0.738% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3084HIGH | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-79Jun 3, 2023 | CVSS8.1v3.1 | EPSS0.841% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3086CRITICAL | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-79Jun 3, 2023 | CVSS9.0v3.1 | EPSS0.909% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3009MEDIUM | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-79May 31, 2023 | CVSS5.4v3.1 | EPSS0.683% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2859HIGH | Code Injection in nilsteampassnet/teampassCode Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. CWE-94May 24, 2023 | CVSS8.8v3.1 | EPSS1.65% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2591MEDIUM | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nilsteampassnet/teampassImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7. | CVSS5.4v3.1 | EPSS0.607% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2516MEDIUM | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7. CWE-79May 5, 2023 | CVSS5.4v3.1 | EPSS0.612% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2021MEDIUM | Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampassCross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3. CWE-79Apr 13, 2023 | CVSS5.4v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1545HIGH | SQL Injection in nilsteampassnet/teampassSQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. CWE-89Mar 21, 2023 | CVSS7.5v3.1 | EPSS8.35% | PoCs5 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1463MEDIUM | Authorization Bypass Through User-Controlled Key in nilsteampassnet/teampassAuthorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | CVSS5.4v3.1 | EPSS0.523% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-1070HIGH | External Control of File Name or Path in nilsteampassnet/teampassExternal Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. CWE-73Feb 27, 2023 | CVSS7.1v3.1 | EPSS0.823% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26980MEDIUM | Cross-site Scripting in teampassTeampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. CWE-79Mar 28, 2022 | CVSS6.1v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11671HIGH | Missing Authorization in TeamPassLack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default. CWE-862May 4, 2020 | CVSS8.1v3.1 | EPSS1.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-12477HIGH | Incorrect Authorization in TeamPassThe REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function. CWE-863Apr 29, 2020 | CVSS7.5v3.1 | EPSS1.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |