PT-2025-12160 · Flatpress · Flatpress
Published
2025-03-20
·
Updated
2025-06-23
·
CVE-2024-4023
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
flatpressblog/flatpress version 1.3
Description
A stored cross-site scripting (XSS) issue exists. When a user uploads a file with a
.xsig extension and directly accesses this file, the server responds with a Content-type of application/octet-stream, leading to the file being processed as an HTML file. This allows an attacker to execute arbitrary JavaScript code, which can be used to steal user cookies, perform HTTP requests, and access content of the same origin.Recommendations
For version 1.3, consider restricting the upload of files with a
.xsig extension to prevent exploitation until a patch is available. As a temporary workaround, avoid directly accessing uploaded files with this extension to minimize the risk of arbitrary JavaScript code execution.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flatpress