CVE-2017-9436

TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
References
Link Resource
https://github.com/nilsteampassnet/TeamPass/blob/master/changelog.md Issue Tracking Patch Third Party Advisory
https://github.com/nilsteampassnet/TeamPass/blob/master/changelog.md Issue Tracking Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:teampass:teampass:2.1.20.0:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.22.0:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.23.1:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.23.2:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.23.3:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.23.4:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.24.0:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.24.1:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.24.2:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.24.3:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.24.4:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.25.0:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.25.1:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.25.2:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.0:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.1:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.2:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.3:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.4:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.5:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.6:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.7:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.8:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.9:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.10:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.11:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.12:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.13:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.14:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.15:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.16:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.17:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.18:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.26.19:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.27.0:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.27.1:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.27.2:*:*:*:*:*:*:*
cpe:2.3:a:teampass:teampass:2.1.27.3:*:*:*:*:*:*:*

History

21 Nov 2024, 03:36

Type Values Removed Values Added
References () https://github.com/nilsteampassnet/TeamPass/blob/master/changelog.md - Issue Tracking, Patch, Third Party Advisory () https://github.com/nilsteampassnet/TeamPass/blob/master/changelog.md - Issue Tracking, Patch, Third Party Advisory

Information

Published : 2017-06-05 14:29

Updated : 2024-11-21 03:36


NVD link : CVE-2017-9436

Mitre link : CVE-2017-9436

CVE.ORG link : CVE-2017-9436


JSON object : View

Products Affected

teampass

  • teampass
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')