FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/paragbagul111/CVE-2024-33209 |
|
History
Wed, 16 Oct 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flatpress
Flatpress flatpress |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:flatpress:flatpress:1.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Flatpress
Flatpress flatpress |
|
| Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-02T00:00:00.000Z
Updated: 2025-03-14T15:50:11.392Z
Reserved: 2024-04-23T00:00:00.000Z
Link: CVE-2024-33209
Updated: 2024-10-02T16:00:31.292Z
Status : Modified
Published: 2024-10-02T16:15:10.300
Modified: 2025-03-14T16:15:31.387
Link: CVE-2024-33209
No data.