Stored XSS Vulnerability in TeamPass by TeamPass Team
CVE-2019-16904

5.4MEDIUM

Key Information:

Vendor

Teampass

Status
Vendor
CVE Published:
26 September 2019

What is CVE-2019-16904?

TeamPass 2.1.27.36 is vulnerable to Stored XSS, allowing attackers to embed malicious scripts by setting a specially crafted password for an item. This vulnerability can be exploited when the change history of the item is viewed or when the item is accessed by an admin. If successful, the script can execute in the context of the user, leading to potential data breaches and unauthorized actions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.