MEDIUM5.4
GHSA-rpmr-fwh5-24fm
TeamPass Cross-site Scripting (XSS) vulnerability
Details
TeamPass 2.1.27.36 allows XSS by setting a crafted password for an item in a folder, and then sharing that item with an admin. (The crafted password is exploitable when viewing the change history, or the previous used password field.)
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nilsteampassnet/teampass
Introduced in:
0No fixed version published yet for nilsteampassnet/teampass (composer). Pin to a known-safe version or switch to an alternative.