Improperly Controlled Modification of Dynamically-Determined Object Attributes in TeamPass - #VU140790
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges to administrator.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the `save_user_change` case handler in `app/sources/users.queries.php` when handling profile-change requests. A remote user can send a specially crafted HTTP request with an attacker-controlled column name to escalate privileges to administrator.
The vulnerable action is accessible to authenticated non-read-only users, and managers can target arbitrary user IDs rather than only their own account.