Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19865 | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through the footer_text and announcement parameters in config.php. |
Solution
The vulnerability has been fixed by the Flatboard Pro team in version 3.2.2.
Workaround
No workaround given by the vendor.
Thu, 03 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Jul 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through the footer_text and announcement parameters in config.php. | |
| Title | Stored Cross-Site Scripting (XSS) vulnerability on Flatboard | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-03T13:15:16.912Z
Reserved: 2025-04-16T08:38:20.493Z
Link: CVE-2025-40723
Updated: 2025-07-03T13:13:38.776Z
Status : Awaiting Analysis
Published: 2025-07-03T12:15:24.933
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-40723
No data.
OpenCVE Enrichment
No data.
EUVD