Back to Database
Status published
Critical
CVE-2017-9436
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in...
Vulnerability Description
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-9436
Credits & Attribution
No credits recorded in the NVD database.
More from teampass
View All →CVE-2022-26980
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO....
Medium
6.1
CVE-2020-12479
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a...
High
8.8
CVE-2020-12478
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from...
High
7.5
CVE-2020-12477
The REST API functions in TeamPass 2.1.27.36 allow any user...
High
7.5
CVE-2020-11671
Lack of authorization controls in REST API functions in TeamPass...
High
8.1
Affected Vendor
teampass
View all reports →Affected Software
teampass
Vulnerable Versions:
2.1.20.0, 2.1.22.0, 2.1.23.1, 2.1.23.2, 2.1.23.3, 2.1.23.4, 2.1.24.0, 2.1.24.1, 2.1.24.2, 2.1.24.3, 2.1.24.4, 2.1.25.0, 2.1.25.1, 2.1.25.2, 2.1.26, 2.1.26.0, 2.1.26.1, 2.1.26.2, 2.1.26.3, 2.1.26.4, 2.1.26.5, 2.1.26.6, 2.1.26.7, 2.1.26.8, 2.1.26.9, 2.1.26.10, 2.1.26.11, 2.1.26.12, 2.1.26.13, 2.1.26.14, 2.1.26.15, 2.1.26.16, 2.1.26.17, 2.1.26.18, 2.1.26.19, 2.1.27.0, 2.1.27.1, 2.1.27.2, 2.1.27.3
Timeline
Official Publish:
June 5th, 2017
Last Modified:
September 16th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.