VYPR
Unrated severityNVD Advisory· Published Aug 1, 2018· Updated Sep 16, 2024

CVE-2018-14776

CVE-2018-14776

Description

Click Studios Passwordstate before 8.3 Build 8397 allows XSS by authenticated users via an uploaded HTML document.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Passwordstate before 8.3 Build 8397 is vulnerable to stored XSS via uploaded HTML documents by authenticated users.

Vulnerability

Passwordstate versions prior to 8.3 Build 8397 are vulnerable to stored cross-site scripting (XSS) through the upload of HTML documents. An authenticated user can upload a crafted HTML file containing malicious JavaScript. The vulnerability exists in the document upload functionality.

Exploitation

An authenticated user with permission to upload documents can upload an HTML file containing embedded JavaScript. When other users view the uploaded document, the script executes in their browser session. The attacker does not require any special privileges beyond standard user access to the upload feature.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking, credential theft, or other actions performed on behalf of the victim. The XSS is stored, meaning it persists on the server and affects all subsequent viewers.

Mitigation

The vulnerability is fixed in Passwordstate version 8.3 Build 8397, as indicated in the vendor's changelog [2]. Users should upgrade to this version or later. No workarounds are documented; upgrading is the recommended action.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.