Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prj5-2g2p-x2mw

Опубликовано: 09 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

teampass vulnerable to code injection

In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7.

Пакеты

Наименование

nilsteampassnet/teampass

composer
Затронутые версииВерсия исправления

< 3.0.7

3.0.7

EPSS

Процентиль: 55%
0.00322
Низкий

7.1 High

CVSS3

Дефекты

CWE-79
CWE-94

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVSS3: 5.4
debian
больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-si ...

EPSS

Процентиль: 55%
0.00322
Низкий

7.1 High

CVSS3

Дефекты

CWE-79
CWE-94