VDB
Sign up
MEDIUM5.4

GHSA-m3pp-jcpm-2vr9

TeamPass Cross-site Scripting (XSS)

Details

An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0

No fixed version published yet for nilsteampassnet/teampass (composer). Pin to a known-safe version or switch to an alternative.

References