PT-2023-25222 · Teampass · Teampass

CVE-2023-3552

·

Publicado

2023-07-08

·

Atualizado

2023-07-14

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions TeamPass versions prior to 3.0.10
Description The issue is related to improper encoding or escaping of output, which can lead to cross-site scripting filter bypass in folder names, potentially resulting in information disclosure.
Recommendations For versions prior to 3.0.10, update to version 3.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive folder names to minimize the risk of exploitation.

Exploit

Correção

DoS

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3552
GHSA-2CV5-QVQ3-6276

Produtos afetados

Teampass