Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-059.txt | third party advisory broken link |
https://teampasswordmanager.com/docs/changelog/#10.135.236 | vendor advisory |