Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
teampass teampass |