CVE-2017-9436

EUVD-2022-3591
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
teampassteampass
2.1.20.0
teampassteampass
2.1.22.0
teampassteampass
2.1.23.1
teampassteampass
2.1.23.2
teampassteampass
2.1.23.3
teampassteampass
2.1.23.4
teampassteampass
2.1.24.0
teampassteampass
2.1.24.1
teampassteampass
2.1.24.2
teampassteampass
2.1.24.3
teampassteampass
2.1.24.4
teampassteampass
2.1.25.0
teampassteampass
2.1.25.1
teampassteampass
2.1.25.2
teampassteampass
2.1.26
teampassteampass
2.1.26.0
teampassteampass
2.1.26.1
teampassteampass
2.1.26.2
teampassteampass
2.1.26.3
teampassteampass
2.1.26.4
teampassteampass
2.1.26.5
teampassteampass
2.1.26.6
teampassteampass
2.1.26.7
teampassteampass
2.1.26.8
teampassteampass
2.1.26.9
teampassteampass
2.1.26.10
teampassteampass
2.1.26.11
teampassteampass
2.1.26.12
teampassteampass
2.1.26.13
teampassteampass
2.1.26.14
teampassteampass
2.1.26.15
teampassteampass
2.1.26.16
teampassteampass
2.1.26.17
teampassteampass
2.1.26.18
teampassteampass
2.1.26.19
teampassteampass
2.1.27.0
teampassteampass
2.1.27.1
teampassteampass
2.1.27.2
teampassteampass
2.1.27.3
𝑥
= Vulnerable software versions