MEDIUM6.1
GHSA-v969-5v7f-pmg2
TeamPass Stored Cross-site Scripting
Details
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nilsteampassnet/teampass
Introduced in:
0No fixed version published yet for nilsteampassnet/teampass (composer). Pin to a known-safe version or switch to an alternative.