CVE-2020-12478

HIGH7.5EPSS 35.6%

TeamPass files are available without authentication

Published: 5/24/2022Modified: 4/24/2024
Also known as:GHSA-83h6-22cp-f22w

Description

TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (3)