Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-26091

Опубликовано: 04 мар. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:teampasswordmanager:team_password_manager:*:*:*:*:*:*:*:*
Версия до 12.162.284 (включая)

EPSS

Процентиль: 20%
0.00063
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
github
11 месяцев назад

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.

EPSS

Процентиль: 20%
0.00063
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79