CVE-2023-2021

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:teampass:teampass:*:*:*:*:*:*:*:*

History

21 Apr 2023, 17:19

Type Values Removed Values Added
CPE cpe:2.3:a:teampass:teampass:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References (CONFIRM) https://huntr.dev/bounties/2e31082d-7aeb-46ff-84d6-9561758e3bf0 - (CONFIRM) https://huntr.dev/bounties/2e31082d-7aeb-46ff-84d6-9561758e3bf0 - Exploit, Patch
References (MISC) https://github.com/nilsteampassnet/teampass/commit/77c541a0151841d1f4ceb0a84ca391e1b526d58d - (MISC) https://github.com/nilsteampassnet/teampass/commit/77c541a0151841d1f4ceb0a84ca391e1b526d58d - Patch
First Time Teampass teampass
Teampass

13 Apr 2023, 12:52

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-13 12:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-2021

Mitre link : CVE-2023-2021

CVE.ORG link : CVE-2023-2021


JSON object : View

Products Affected

teampass

  • teampass
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')