teampass vulnerable to code injection
High severity
GitHub Reviewed
Published
May 9, 2023
to the GitHub Advisory Database
•
Updated Nov 11, 2023
Description
Published by the National Vulnerability Database
May 9, 2023
Published to the GitHub Advisory Database
May 9, 2023
Reviewed
May 10, 2023
Last updated
Nov 11, 2023
In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7.
References