CVE-2020-12479: Teampass
High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.
Affected products
- Teampass Teampass: version 2.1.27.36 only
Published 2020-04-29. Last modified 2026-06-17.