MEDIUM
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9
Published Oct 12, 2017
5.4
MEDIUMCVSS 3.0
EPSS 0.95%
Description
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-28pv-2j2h-fmhc Advisory
- https://github.com/nilsteampassnet/TeamPass/blob/master/changelog.md x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://github.com/nilsteampassnet/TeamPass/commit/f5a765381f051fe624386866ddb1f6b5e7eb929b x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/nilsteampassnet/TeamPass/releases/tag/2.1.27.9 x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-15278
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-28pv-2j2h-fmhc | Advisory | |
| https://github.com/nilsteampassnet/TeamPass/blob/master/changelog.md | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://github.com/nilsteampassnet/TeamPass/commit/f5a765381f051fe624386866ddb1f6b5e7eb929b | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://github.com/nilsteampassnet/TeamPass/releases/tag/2.1.27.9 | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-15278 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 12, 2017
Updated Aug 5, 2024
Reserved Oct 11, 2017
Link CVE-2017-15278
CISA Vulnrichment
GHSA-28PV-2J2H-FMHC Updated n/a