Cross-site scripting in TeamPass - #VU151658

 

Cross-site scripting in TeamPass - #VU151658

Published: September 22, 2026


Vulnerability identifier: #VU151658
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in another user's browser.

The vulnerability exists due to improper neutralization of input during web page generation in the loadItemHistory item-history rendering of value.detail when processing previous item-field values in audit-log history entries. A remote user can store a crafted item field value and later edit the field to execute arbitrary script in another user's browser.

User interaction is required to open the affected item.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.2.1

External References

Related Security Bulletins