Vulnerabilities > CVE-2020-12477 - Incorrect Authorization vulnerability in Teampass 2.1.27.36
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |