PT-2023-20355 · Teampass · Teampass

Published

2023-05-09

·

Updated

2023-05-15

·

CVE-2023-2591

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions teampass versions prior to 3.0.7
Description The issue is related to improper neutralization of input during web page generation, also known as cross-site scripting. In the GitHub repository nilsteampassnet/teampass, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form.
Recommendations For versions prior to 3.0.7, update to version 3.0.7 to resolve the issue. As a temporary workaround, consider restricting access to items that may contain malicious labels to minimize the risk of exploitation. Avoid using the label field in items until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-2591
GHSA-PRJ5-2G2P-X2MW

Affected Products

Teampass