Security Advisory

CVE-2025-26091

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-04 00:00:00
Last updated 2025-04-09 18:27:25
Assigner mitre
State PUBLISHED

Description

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the name parameter when creating a new password in the "My Passwords" page.