Record summary

CVE-2020-12478 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory2.1.27.36affected

Nuclei templates

1
ProjectDiscoveryHIGHTeamPass 2.1.27.36 - Improper AuthenticationCVSS 7.5

TeamPass 2.1.27.36 is susceptible to improper authentication. An attacker can retrieve files from the TeamPass web root, which may include backups or LDAP debug files, and therefore possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can bypass authentication and gain unauthorized access to sensitive information.

Remediation

Upgrade to a patched version of TeamPass or apply the recommended security patches.

WeaknessesCWE-306
Authorsarafatansari
Template tagscve2020cveteampassexposureunauthvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:teampass:teampass:2.1.27.36:*:*:*:*:*:*:*
Shodan: http.html:"teampass"
FOFA: body="teampass"

Source: ProjectDiscovery

References

3