PT-2019-14856 · Teampass · Teampass
Lebiko
·
Published
2019-09-26
·
Updated
2022-05-24
·
CVE-2019-16904
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TeamPass version 2.1.27.36
Description
The issue allows for Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. The crafted password is exploitable when viewing the change history of the item or tapping on the item. This can also occur when sharing an item with an admin and the crafted password is viewed in the change history or the previous used password field.
Recommendations
For TeamPass version 2.1.27.36, as a temporary workaround, consider restricting the ability to set crafted passwords for items in common available folders or shared with admins until a patch is available. Avoid using the
password field in a way that could introduce malicious code, especially when sharing items with admins or viewing change histories.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teampass