PT-2023-20355 · Teampass · Teampass
Published
2023-05-09
·
Updated
2023-05-15
·
CVE-2023-2591
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
teampass versions prior to 3.0.7
Description
The issue is related to improper neutralization of input during web page generation, also known as cross-site scripting. In the GitHub repository nilsteampassnet/teampass, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form.
Recommendations
For versions prior to 3.0.7, update to version 3.0.7 to resolve the issue. As a temporary workaround, consider restricting access to items that may contain malicious labels to minimize the risk of exploitation. Avoid using the label field in items until the issue is resolved.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teampass