Cross-site scripting in TeamPass - #VU151638
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper validation of proxy headers and improper output encoding in the failed-login log renderer when processing a failed login request. A remote attacker can send a failed login request with crafted proxy-header data to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the failed-login log.