CVE-2019-16904
Last modified
CVE-2019-16904 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.). EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Teampass | Teampass | 2.1.27.36 |
References
- https://github.com/nilsteampassnet/TeamPass/issues/2685Exploit, Third Party Advisory
- https://github.com/nilsteampassnet/TeamPass/issues/2685Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-16904?
How severe is CVE-2019-16904?
How do I fix CVE-2019-16904?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-16899In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Fa…7.5
- CVE-2019-1690A vulnerability in the management interface of Cisco Applica…6.5
- CVE-2019-16900Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Wr…7.5
- CVE-2019-16901Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Hand…7.5
- CVE-2019-16902In the ARforms plugin 3.7.1 for WordPress, arf_delete_file i…7.5
- CVE-2019-16903Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/P…5.3
- CVE-2019-16905OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled wi…7.8
- CVE-2019-16906An issue was discovered in the Infosysta "In-App & Desktop N…7.5
- CVE-2019-16907An issue was discovered in the Infosysta "In-App & Desktop N…5.3
- CVE-2019-16908An issue was discovered in the Infosysta "In-App & Desktop N…5.3
- CVE-2019-16909An issue was discovered in the Infosysta "In-App & Desktop N…4.3
- CVE-2019-1691A vulnerability in the detection engine of Cisco Firepower T…5.8
Are you affected by CVE-2019-16904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
