MEDIUM5.8
GHSA-4h2q-84w7-4mhx
nilsteampassnet/teampass vulnerable to stored cross-site scripting (XSS)
Quick fix
GHSA-4h2q-84w7-4mhx — nilsteampassnet/teampass: upgrade to the fixed version with the command below.
composer require nilsteampassnet/teampass:^3.0.3Details
nilsteampassnet/teampass prior to 3.0.3 is vulnerable to stored cross-site scripting (XSS) in the description parameter of a folder.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nilsteampassnet/teampass
Introduced in:
0Fixed in: 3.0.3Fix
composer require nilsteampassnet/teampass:^3.0.3