Stored XSS Vulnerability in TeamPass by TeamPass Team
CVE-2019-16904
5.4MEDIUM
What is CVE-2019-16904?
TeamPass 2.1.27.36 is vulnerable to Stored XSS, allowing attackers to embed malicious scripts by setting a specially crafted password for an item. This vulnerability can be exploited when the change history of the item is viewed or when the item is accessed by an admin. If successful, the script can execute in the context of the user, leading to potential data breaches and unauthorized actions.
