Описание
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.1.27.8 (включая)
cpe:2.3:a:teampass:teampass:*:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00292
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
debian
почти 8 лет назад
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. ...
EPSS
Процентиль: 52%
0.00292
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79