PT-2023-25222 · Teampass · Teampass

Published

2023-07-08

·

Updated

2023-07-14

·

CVE-2023-3552

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions TeamPass versions prior to 3.0.10
Description The issue is related to improper encoding or escaping of output, which can lead to cross-site scripting filter bypass in folder names, potentially resulting in information disclosure.
Recommendations For versions prior to 3.0.10, update to version 3.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive folder names to minimize the risk of exploitation.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2023-3552
GHSA-2CV5-QVQ3-6276

Affected Products

Teampass