VDB
Sign up
MEDIUM4.9

GHSA-5qr3-4839-88gf

TeamPass Improper Privilege Management

Quick fix

GHSA-5qr3-4839-88gf — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^2.1.27.9

Details

TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_user" on users.queries.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 2.1.27.9
Fixcomposer require nilsteampassnet/teampass:^2.1.27.9

References