-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nilsteampassnet/teampass | composer | < 2.1.27.9 | 2.1.27.9 |
The patch adds FILTER_SANITIZE_STRING filtering to URL/login fields in items.queries.php, indicating these were unsanitized input vectors. The vulnerability description explicitly mentions these two injection points (item URL and user log history). The commit shows historical data was rendered with htmlspecialchars_decode() without output encoding in log display logic, and the user profile -> admin log flow matches the second attack vector described.
Ongoing coverage of React2Shell