Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
Any version before 3.1.3.1
affected
Description
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.
Problem types
CWE-266 Incorrect Privilege Assignment
Product status
Any version before 3.1.3.1
References
github.com/nilsteampassnet/TeamPass/compare/3.1.3...3.1.3.1
github.com/nilsteampassnet/TeamPass/compare/3.1.2...3.1.3.1
github.com/...ommit/35e2b479f2379545b4132bc30a9d052ba7018bf9
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.