Описание
TeamPass Stored Cross-site Scripting
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
Пакеты
Наименование
nilsteampassnet/teampass
composer
Затронутые версииВерсия исправления
<= 2.1.27.36
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
больше 6 лет назад
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
CVSS3: 6.1
debian
больше 6 лет назад
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the usern ...