ZeroHour

CVE-2024-33209

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p57
Published
()
Modified
Description

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.

Vendors
flatpress
Products
flatpress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.