PT-2019-14856 · Teampass · Teampass

Lebiko

·

Published

2019-09-26

·

Updated

2022-05-24

·

CVE-2019-16904

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TeamPass version 2.1.27.36
Description The issue allows for Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. The crafted password is exploitable when viewing the change history of the item or tapping on the item. This can also occur when sharing an item with an admin and the crafted password is viewed in the change history or the previous used password field.
Recommendations For TeamPass version 2.1.27.36, as a temporary workaround, consider restricting the ability to set crafted passwords for items in common available folders or shared with admins until a patch is available. Avoid using the password field in a way that could introduce malicious code, especially when sharing items with admins or viewing change histories.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16904
GHSA-RPMR-FWH5-24FM

Affected Products

Teampass