CVE-2017-15051

    Dashboard / Vulnerabilities / CVE-2017-15051

    CVE-2017-15051

    Published: 27 Nov 2017Last Modified: 8 Jul 2026

    Summary:

    Details: Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first authenticated to the application. For the first one, the attacker has to simply inject XSS code within the URL field of a shared item. For the second one however, the attacker must prepare a payload within its profile, and then ask an administrator to modify its profile. From there, whenever the administrator accesses the log, it can be XSS'ed.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    2.1.27.8
    2.1.27.7
    2.1.27.6
    2.1.27.5
    2.1.27.4
    2.1.27.3
    2.1.27.2
    2.1.27.1
    2.1.27.0
    2.1.26-final-3
    2.1.26-final-2
    2.1.26-final
    2.1.26
    2.1.26.17
    2.1.26.16
    2.1.26.15
    2.1.26.14
    2.1.26.13
    2.1.26.12
    2.1.26.11
    2.1.26.10
    2.1.26.9
    2.1.26.8
    2.1.26.7
    2.1.26.6
    2.1.26.5
    2.1.26.4
    2.1.26.3
    2.1.26.2
    2.1.26.1
    2.1.26.0
    2.1.25.2
    2.1.25.1
    2.1.25.0
    2.1.20

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2017-15051 | CVE-DB