PT-2025-21942 · Unknown · Flatpress Cms
Harish0X
·
Published
2025-05-19
·
Updated
2025-06-12
·
CVE-2025-44108
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Flatpress CMS versions prior to 1.4
Description:
A stored Cross-Site Scripting (XSS) issue exists in the administration panel of Flatpress CMS via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
Recommendations:
For versions prior to 1.4, update to version 1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the administration panel and the gallery captions component to minimize the risk of exploitation. Avoid using the gallery captions component until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flatpress Cms