Vulnerabilities
Vulnerable Software
Sismics:  >> Teedy  >> 1.10  Security Vulnerabilities
A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Executing manipulation can lead to improper access controls. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
6.3
EPSS Score
0.0
Published
2025-10-16
Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-01-29
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.
CVSS Score
9.8
EPSS Score
0.021
Published
2025-01-29
Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-01-13


Contact Us

Shodan ® - All rights reserved