FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/paragbagul111/CVE-2024-33209 |
History
Wed, 16 Oct 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Flatpress
Flatpress flatpress |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:flatpress:flatpress:1.3:*:*:*:*:*:*:* | |
Vendors & Products |
Flatpress
Flatpress flatpress |
|
Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-02T00:00:00
Updated: 2024-10-02T16:00:41.395Z
Reserved: 2024-04-23T00:00:00
Link: CVE-2024-33209
Vulnrichment
Updated: 2024-10-02T16:00:31.292Z
NVD
Status : Analyzed
Published: 2024-10-02T16:15:10.300
Modified: 2024-10-16T13:33:21.313
Link: CVE-2024-33209
Redhat
No data.