SQL injection in TeamPass - #VU140788
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to sql injection in app/sources/users.logs.datatable.php when handling the top-level dir parameter in the ORDER BY clause. A remote user can send a specially crafted request to disclose sensitive information.
The affected endpoint is reachable by a baseline authenticated user role, and the injection supports error-based, boolean-based, and time-based extraction techniques.