MEDIUM6.1
GHSA-m2wv-m5pf-284r
Cross-site Scripting in teampass
Details
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. Someone must open a link for the Teampass Password Manager index page containing malicious payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nilsteampassnet/teampass
Introduced in:
0No fixed version published yet for nilsteampassnet/teampass (composer). Pin to a known-safe version or switch to an alternative.