CVE-2014-3772: Teampass

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that calls the session_start function before checking the CPM key, as demonstrated by a request to sources/upload/upload.files.php.

Affected products

  • Teampass Teampass: up to and including 2.1.20; version 2.1 only; version 2.1.1 only; version 2.1.2 only; version 2.1.3 only; version 2.1.4 only; …

Published 2014-08-07. Last modified 2026-06-17.