Vulnerability Description
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teampasswordmanager | Team Password Manager | <= 7.93.204 |
Related Weaknesses (CWE)
References
- https://teampasswordmanager.com/docs/changelog/ProductRelease Notes
- https://www.pentagrid.ch/de/blog/security_issues_in_teampasswordmanager_and_combThird Party Advisory
- https://teampasswordmanager.com/docs/changelog/ProductRelease Notes
- https://www.pentagrid.ch/de/blog/security_issues_in_teampasswordmanager_and_combThird Party Advisory
FAQ
What is CVE-2019-19461?
CVE-2019-19461 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
How severe is CVE-2019-19461?
CVE-2019-19461 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19461?
Check the references section above for vendor advisories and patch information. Affected products include: Teampasswordmanager Team Password Manager.