VDB
Sign up
MEDIUM5.4

GHSA-qmw8-x364-xxxm

Teampass Cross-site Scripting vulnerability

Quick fix

GHSA-qmw8-x364-xxxm — nilsteampassnet/teampass: upgrade to the fixed version with the command below.

composer require nilsteampassnet/teampass:^3.0.9

Details

In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nilsteampassnet/teampass
Introduced in: 0Fixed in: 3.0.9
Fixcomposer require nilsteampassnet/teampass:^3.0.9

References