Stored XSS Vulnerability in TeamPass by Nils Teampassnet
CVE-2019-17204

5.4MEDIUM

Key Information:

Vendor

Teampass

Status
Vendor
CVE Published:
5 October 2019

What is CVE-2019-17204?

TeamPass version 2.1.27.36 is susceptible to a stored cross-site scripting (XSS) vulnerability. This flaw allows an attacker to inject malicious scripts into the Knowledge Base by creating a specifically crafted label. When other users access the compromised component, the injected script executes in their browsers, potentially leading to unauthorized actions and data exposure. It is crucial for users of this version to implement security measures and update to mitigate the risk associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.