VDB
Sign up
HIGH7.1

GHSA-prj5-2g2p-x2mw

teampass vulnerable to code injection

Quick fix

GHSA-prj5-2g2p-x2mw — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^3.0.7

Details

In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 3.0.7
Fixcomposer require nilsteampassnet/teampass:^3.0.7

References