CVE-2025-26091

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.
References
Link Resource
https://brunocaseiro.github.io/CVE-2025-26091/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:teampasswordmanager:team_password_manager:*:*:*:*:*:*:*:*

History

21 May 2025, 15:00

Type Values Removed Values Added
References () https://brunocaseiro.github.io/CVE-2025-26091/ - () https://brunocaseiro.github.io/CVE-2025-26091/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:teampasswordmanager:team_password_manager:*:*:*:*:*:*:*:*
First Time Teampasswordmanager team Password Manager
Teampasswordmanager

09 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
Summary
  • (es) Vulnerabilidad de Cross Site Scripting (XSS) en TeamPasswordManager v12.162.284 y anteriores podría permitir a un atacante remoto ejecutar JavaScript arbitrario en el navegador del usuario, incluyendo un payload malicioso en el parámetro 'name' al crear una nueva contraseña en la página "Mis contraseñas" ("My Passwords").
CWE CWE-79

04 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 17:15

Updated : 2025-05-21 15:00


NVD link : CVE-2025-26091

Mitre link : CVE-2025-26091

CVE.ORG link : CVE-2025-26091


JSON object : View

Products Affected

teampasswordmanager

  • team_password_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')