VDB
Sign up
CRITICAL9.8

GHSA-cm26-gp8j-w6xf

TeamPass SQL injection in users.queries.php

Quick fix

GHSA-cm26-gp8j-w6xf — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^2.1.27.5

Details

TeamPass before 2.1.27.5 is vulnerable to a SQL injection in users.queries.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 2.1.27.5
Fixcomposer require nilsteampassnet/teampass:^2.1.27.5

References