← Back

CVE-2014-3774

nvd nist
Published: Aug 7, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in items.php in TeamPass before 2.1.20 allow remote attackers to inject arbitrary web script or HTML via the group parameter, which is not properly handled in a (1) hid_cat or (2) open_folder form element, or (3) id parameter, which is not properly handled in the open_id form element.

Affected (13)

Products: Teampass: Teampass
1 product
Teampass
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Teampass
Up to 2.1.20
Version 2.1.10
Version 2.1.13
Version 2.1.14
Version 2.1.15
Version 2.1.18
Version 2.1.19
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1

Timeline

No history available yet.