PT-2021-10786 · Flatpress · Flatpress

Lethanhtrung222

·

Published

2021-07-29

·

Updated

2024-02-14

·

CVE-2020-22761

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FlatPress version 1.1
Description A Cross Site Request Forgery (CSRF) issue exists, allowing unauthorized actions. The DeleteFile function in flat/admin.php is affected.
Recommendations For FlatPress version 1.1, consider disabling the DeleteFile function in flat/admin.php until a patch is available to prevent unauthorized file deletions.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-22761

Affected Products

Flatpress