PT-2026-29213 · Teampass · Teampass
Publicado
2026-03-31
·
Atualizado
2026-03-31
·
CVE-2026-3107
CVSS v4.0
9.3
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Teampass versions prior to 3.1.5.16
Description
A stored Cross-Site Scripting (XSS) issue exists in Teampass affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application does not properly sanitize and encode user-input data during the import process, allowing malicious JavaScript payloads to be persistently stored in the database. When other users view the imported passwords, the payload is automatically executed in their browsers, resulting in a stored XSS condition at the endpoint 'redacted/index.php?page=items'. Exploiting this issue allows an attacker to execute arbitrary JavaScript code in the context of multiple users and the administrator, potentially leading to session hijacking, credential theft, and compromise of application integrity.
Recommendations
Update Teampass to version 3.1.5.16 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Teampass