PT-2025-7772 · Flatpress · Flatpress
Athul S
·
Published
2025-02-24
·
Updated
2025-02-24
·
CVE-2025-25460
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FlatPress version 1.3.1
Description
A stored Cross-Site Scripting issue was identified within the "Add Entry" feature, allowing authenticated attackers to inject malicious JavaScript payloads into blog posts. This is executed when other users view the posts due to improper input sanitization of the
TextArea field in the blog entry submission form.Recommendations
For FlatPress version 1.3.1, ensure proper input sanitization of the
TextArea field in the blog entry submission form to prevent malicious JavaScript injections. As a temporary workaround, consider restricting access to the "Add Entry" feature until a fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flatpress