MEDIUM5.4
GHSA-28pv-2j2h-fmhc
TeamPass Cross-Site Scripting (XSS)
Quick fix
GHSA-28pv-2j2h-fmhc — nilsteampassnet/teampass: upgrade to the fixed version with the command below.
composer require nilsteampassnet/teampass:^2.1.27.9Details
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nilsteampassnet/teampass
Introduced in:
0Fixed in: 2.1.27.9Fix
composer require nilsteampassnet/teampass:^2.1.27.9References
- https://nvd.nist.gov/vuln/detail/CVE-2017-15278[ADVISORY]
- https://github.com/nilsteampassnet/TeamPass/commit/f5a765381f051fe624386866ddb1f6b5e7eb929b[WEB]
- https://github.com/nilsteampassnet/TeamPass[PACKAGE]
- https://github.com/nilsteampassnet/TeamPass/blob/master/changelog.md[WEB]
- https://github.com/nilsteampassnet/TeamPass/releases/tag/2.1.27.9[WEB]