Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://huntr.dev/bounties/d7b8ea75-c74a-4721-89bb-12e5c80fb0ba | patch third party advisory exploit |
https://github.com/nilsteampassnet/teampass/commit/1f51482a0c4d152ca876844212b0f8f3cb9387af | patch |