Stored XSS in many configuration fields in nilsteampassnet/teampass
Valid
Reported on
Jun 4th 2023
Description
Paste the XSS payload into the configuration fields. And I think there are many fields to configure that can be vulnerable to Stored XSS vulnerabilities, such as configuration fields in Options, MFA, API, Emails,... hope you check it too.
Proof of Concept
https://drive.google.com/file/d/1RDoq3qFFiWsIPltiAFlum5V0wYfZ41FN/view
Acknowledge
Tran Van Nhan from bl4ckh0l3 of GalaxyOne
Impact
This can potentially lead to a range of serious consequences, such as theft of sensitive data, unauthorized access to systems, and the ability to carry out further attacks.
We are processing your report and will contact the
nilsteampassnet/teampass
team within 24 hours.
4 months ago
Tran Van Nhan modified the report
4 months ago
Tran Van Nhan modified the report
4 months ago
Tran Van Nhan modified the report
4 months ago
We have contacted a member of the
nilsteampassnet/teampass
team and are waiting to hear back
4 months ago
The researcher's credibility has increased: +7
The fix bounty has been dropped
This vulnerability has been assigned a CVE
Thank you
The researcher's credibility has slightly increased as a result of the maintainer's thanks: +1
to join this conversation