VDB
Sign up
MEDIUM4.9

GHSA-xvjf-394g-phrr

TeamPass Improper Privilege Management

Quick fix

GHSA-xvjf-394g-phrr — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^2.1.27.9

Details

TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_role" on roles.queries.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 2.1.27.9
Fixcomposer require nilsteampassnet/teampass:^2.1.27.9

References