CVE-2024-33209

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.
References
Link Resource
https://github.com/paragbagul111/CVE-2024-33209 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:flatpress:flatpress:1.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-02 16:15

Updated : 2025-03-14 16:15


NVD link : CVE-2024-33209

Mitre link : CVE-2024-33209

CVE.ORG link : CVE-2024-33209


JSON object : View

Products Affected

flatpress

  • flatpress
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')