Cross-Site Scripting (XSS) in flatpressblog/flatpress
Vulnerability Description
A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version 1.4.dev.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9699
Credits & Attribution
No credits recorded in the NVD database.
References
More from flatpressblog
View All →Affected Vendor
flatpressblog
View all reports →