Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TeamPass 安全漏洞
Vulnerability Description
TeamPass是NILS LAUMAILL?软件开发者的一款开源的密码管理器。 TeamPass 2.1.27.36及之前版本中的REST API功能存在安全漏洞。攻击者可利用该漏洞获取TeamPass管理员权限,读取或修改所有密码。
CVSS Information
N/A
Vulnerability Type
N/A