Impact
PasswordPusher before version 2.8.1 accepts data payloads due to a CWE-183 vulnerability where the server‑side validation function does not reject data URI schemes. An attacker can craft a link containing a data:text/html URI that embeds malicious JavaScript; when a victim clicks the link the script runs in the victim’s browser under the PasswordPusher domain, allowing phishing and credential theft.
Affected Systems
All PasswordPusher installations running a version older than 2.8.1 are considered affected; does not list explicit sub‑versions, so any build prior to the 2.8.1 update is vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate to high impact potential. The EPSS score is less than 1%, and not listed in CISA’s KEV catalog. Exploitation requires the victim to click the malicious link, meaning user interaction is a prerequisite; nevertheless, because the attack executes within the trusted domain it can effectively compromise credentials, presenting a significant risk for organizations relying on PasswordPusher to store sensitive information.
OpenCVE Enrichment