PT-2020-15000 · Flatcore · Flatcore

Azrul Ikhwan Zulkifli

+1

·

Published

2020-08-09

·

Updated

2020-08-10

·

CVE-2020-17451

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions flatCore versions prior to 1.5.7
Description The issue allows for XSS by an admin via specific parameters in the "acp/acp.php" endpoint, including page linkname, page title, page content, or page extracontent when editing a page, or prefs pagename, prefs pagetitle, or prefs pagesubtitle when setting system preferences.
Recommendations For versions prior to 1.5.7, update to version 1.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the "acp/acp.php" endpoint, specifically the tn=pages&sub=edit and tn=system&sub=sys pref sections, to minimize the risk of exploitation. Avoid using the vulnerable parameters page linkname, page title, page content, page extracontent, prefs pagename, prefs pagetitle, or prefs pagesubtitle in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-17451

Affected Products

Flatcore