CVE-2020-12478
TeamPass files are available without authentication
Record summary
CVE-2020-12478 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
nilsteampassnet/teampassBrowse Packagist / nilsteampassnet/teampass | GitHub Advisory | 2.1.27.36 | affected |
Nuclei templates
1ProjectDiscoveryHIGHTeamPass 2.1.27.36 - Improper AuthenticationCVSS 7.5
TeamPass 2.1.27.36 is susceptible to improper authentication. An attacker can retrieve files from the TeamPass web root, which may include backups or LDAP debug files, and therefore possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can bypass authentication and gain unauthorized access to sensitive information.
Remediation
Upgrade to a patched version of TeamPass or apply the recommended security patches.
Source: ProjectDiscovery