Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Teampasswordmanager Team_Password_Manager
cpe:2.3:a:teampasswordmanager:team_password_manager:*:*:*:*:*:*:*:*
|
— |
14.184.308
|