Stored XSS Vulnerability in TeamPass by Nilsteampassnet
CVE-2019-17203

5.4MEDIUM

Key Information:

Vendor

Teampass

Status
Vendor
CVE Published:
5 October 2019

What is CVE-2019-17203?

A vulnerability in TeamPass 2.1.27.36 allows for stored XSS exploitation through the application’s Search page. By submitting a specially crafted password for an item in any folder, an attacker can execute malicious scripts within the context of the application. This could lead to unauthorized actions on behalf of users who access the infected pages, potentially compromising sensitive information. Users of TeamPass should be aware of this risk and apply necessary security measures.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.