Stored XSS on items in Folder in nilsteampassnet/teampass lead to ATO in nilsteampassnet/teampass

Valid

Reported on

May 7th 2023


Description

Stored XSS on items in Folder in nilsteampassnet/teampass lead to ATO

Proof of Concept

POC on my Drive video: https://drive.google.com/file/d/1OsksHJxcaNNABIoabL_AwAKCu37S2VyT/view?usp=sharing

Impact

Administrator view List User and script triggered, attacker can use a script send cokkie to burp collaborator or attacker server on Internet, lead to Account Takeover. Attacker can do everything an administrator can do it.

We are processing your report and will contact the nilsteampassnet/teampass team within 24 hours. 4 months ago
tadjmen
4 months ago

Researcher


Sorry for ATO, just Stored XSS

We have contacted a member of the nilsteampassnet/teampass team and are waiting to hear back 4 months ago
Nils Laumaillé validated this vulnerability 4 months ago
tadjmen has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
Nils Laumaillé marked this as fixed in 3.0.9 with commit 1c0825 4 months ago
The fix bounty has been dropped
This vulnerability has been assigned a CVE
Nils Laumaillé published this vulnerability 4 months ago
Nils Laumaillé gave praise 4 months ago
Thank you
The researcher's credibility has slightly increased as a result of the maintainer's thanks: +1
to join this conversation