PT-2025-12290 · Unknown · Flatpress Cms
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-9699
CVSS v3.1
7.5
High
| Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FlatPress CMS versions prior to 1.4.dev
Description
A issue in the file upload functionality of the admin panel allows an attacker to upload a file with a JavaScript payload disguised as a filename, potentially leading to a Cross-Site Scripting (XSS) attack if other users access the uploaded file.
Recommendations
For versions prior to 1.4.dev, update to version 1.4.dev to resolve the issue. As a temporary workaround, consider restricting access to the file upload functionality in the admin panel until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flatpress Cms