VDB
Sign up
HIGH7.6

GHSA-2cv5-qvq3-6276

TeamPass vulnerable to Improper Encoding or Escaping of Output

Quick fix

GHSA-2cv5-qvq3-6276 — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^3.0.10

Details

TeamPass prior to 3.0.10 is vulnerable to cross-site scripting filter bypass in folder names. This can lead to information disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 3.0.10
Fixcomposer require nilsteampassnet/teampass:^3.0.10

References