Логотип exploitDog
bind:CVE-2017-15052
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-15052

Количество 3

Количество 3

nvd логотип

CVE-2017-15052

около 8 лет назад

TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_user" on users.queries.php.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2017-15052

около 8 лет назад

TeamPass before 2.1.27.9 does not properly enforce manager access cont ...

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-5qr3-4839-88gf

больше 3 лет назад

TeamPass Improper Privilege Management

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-15052

TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_user" on users.queries.php.

CVSS3: 4.9
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-15052

TeamPass before 2.1.27.9 does not properly enforce manager access cont ...

CVSS3: 4.9
0%
Низкий
около 8 лет назад
github логотип
GHSA-5qr3-4839-88gf

TeamPass Improper Privilege Management

CVSS3: 4.9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу