PT-2023-2987 · Teampass · Teampass
Published
2023-05-31
·
Updated
2023-06-06
·
CVE-2023-3009
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
teampass versions prior to 3.0.9
Description
The issue is related to a Cross-site Scripting (XSS) - Stored vulnerability in the teampass GitHub repository. This vulnerability is associated with the lack of protection measures for the web page structure, allowing a remote attacker to perform inter-site script attacks. The exploitation of this vulnerability enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder.
Recommendations
For versions prior to 3.0.9, update to version 3.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to shared folders to minimize the risk of exploitation. Avoid using shared folders until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teampass