VDB
Sign up
MEDIUM5.4

GHSA-h5g9-2p35-54c7

nilsteampassnet/teampass vulnerable to cross-site scripting

Quick fix

GHSA-h5g9-2p35-54c7 — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^3.0.9

Details

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. This enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 3.0.9
Fixcomposer require nilsteampassnet/teampass:^3.0.9

References