PT-2023-2987 · Teampass · Teampass

Published

2023-05-31

·

Updated

2023-06-06

·

CVE-2023-3009

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions teampass versions prior to 3.0.9
Description The issue is related to a Cross-site Scripting (XSS) - Stored vulnerability in the teampass GitHub repository. This vulnerability is associated with the lack of protection measures for the web page structure, allowing a remote attacker to perform inter-site script attacks. The exploitation of this vulnerability enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder.
Recommendations For versions prior to 3.0.9, update to version 3.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to shared folders to minimize the risk of exploitation. Avoid using shared folders until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03011
CVE-2023-3009
GHSA-H5G9-2P35-54C7

Affected Products

Teampass