Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an actiononquickicon action to item.query.php or the (2) order or (3) direction parameter in an (a) connectionslogs, (b) errorslogs or (c) accesslogs action to view.query.php.
{
"github_reviewed": true,
"nvd_published_at": "2017-04-12T22:59:00Z",
"severity": "CRITICAL",
"github_reviewed_at": "2025-04-22T17:33:24Z",
"cwe_ids": [
"CWE-89"
]
}