CVE-2017-15278 describes a Cross-Site Scripting (XSS) vulnerability in TeamPass versions prior to 2.1.27.9, stemming from insufficient input sanitization in the /sources/folders.queries.php file. This medium-severity vulnerability (CVSS 5.4) allows an authenticated attacker to execute arbitrary HTML and script code in a victim's browser through user interaction, potentially leading to information disclosure or session hijacking. While the EPSS score indicates a low likelihood of exploitation, there is no public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.27.8CPE matchmatch criteria | cpe:2.3:a:teampass:teampass:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.