The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Access Restriction Bypass vulnerabilities in an interactive lesson.
Start learningUpgrade nilsteampassnet/teampass
to version 2.1.27.9 or higher.
nilsteampassnet/teampass is a Collaborative Passwords Manager.
Affected versions of this package are vulnerable to Access Restriction Bypass.It does not properly enforce item access control when requesting items.queries.php.
It is then possible to copy any arbitrary item into a directory controlled by the attacker. To exploit the vulnerability, an authenticated attacker must tamper with the requests sent directly, for example by changing the item_id
parameter when invoking copy_item
on items.queries.php
.