Stored cross-site scripting in TeamPass - CVE-2019-17205
Published: October 7, 2019 / Updated: April 14, 2023
TeamPass
Nils Laumaillé
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in log of Failed Logins. A remote attacker can place a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.