-
CVSS Score
-The vulnerability occurs because a crafted password is stored and later rendered unsafely. Two key points of failure are identified: 1) Client-side JavaScript handling password disclosure (high confidence) - the infinite XSS trigger on password reveal strongly suggests insecure DOM manipulation. 2) Server-side HTML generation (medium confidence) - stored XSS typically requires improper output encoding during page rendering. The confidence levels reflect the attack pattern described, though exact function names/paths are inferred based on common implementation patterns in web applications.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nilsteampassnet/teampass | composer | <= 2.1.27.36 |