A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Jun 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Flatpress
Flatpress flatpress |
|
CPEs | cpe:2.3:a:flatpress:flatpress:1.3.1:*:*:*:*:*:*:* | |
Vendors & Products |
Flatpress
Flatpress flatpress |
Mon, 24 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Mon, 24 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-24T16:52:23.129Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25460

Updated: 2025-02-24T16:51:41.927Z

Status : Analyzed
Published: 2025-02-24T16:15:14.873
Modified: 2025-06-12T20:14:41.587
Link: CVE-2025-25460

No data.

No data.