Stored Cross-Site Scripting in TeamPass by Nilsteampassnet
CVE-2019-17205

6.1MEDIUM

Key Information:

Vendor

Teampass

Status
Vendor
CVE Published:
5 October 2019

What is CVE-2019-17205?

A vulnerability in TeamPass 2.1.27.36 permits stored Cross-Site Scripting (XSS) attacks due to improper handling of user-generated input. When an attacker inputs a crafted payload in the username field during login attempts, this malicious script can be executed when an administrator views the log of failed login attempts. This poses significant risks, including unauthorized actions and data exposure, highlighting the need for immediate remediation.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.