CVE-2017-15052: Improper Privilege Management
(updated )
TeamPass does not properly enforce manager access control when requesting users.queries.php
. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator.
References
Detect and mitigate CVE-2017-15052 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →