CVE-2017-15053 — TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application — CVE Database · The Intelligence Room