CVE-2024-9847

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticated user, will send a request to the FlatPress CMS server to perform the desired action on behalf of the victim user. Since the request is authenticated, the server will process it as if it were initiated by the legitimate user, effectively allowing the attacker to perform unauthorized actions. This vulnerability is fixed in version 1.4.dev.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flatpress:flatpress:*:*:*:*:*:*:*:*

History

24 Jun 2025, 14:38

Type Values Removed Values Added
First Time Flatpress
Flatpress flatpress
Summary
  • (es) La última versión de FlatPress CMS es vulnerable a ataques de Cross-Site Request Forgery (CSRF), que permiten a un atacante habilitar o deshabilitar complementos en nombre de un usuario víctima. El atacante puede manipular un enlace o script malicioso que, al hacer clic en él un usuario autenticado, enviará una solicitud al servidor de FlatPress CMS para realizar la acción deseada en nombre del usuario víctima. Dado que la solicitud está autenticada, el servidor la procesará como si la hubiera iniciado el usuario legítimo, lo que permite al atacante realizar acciones no autorizadas. Esta vulnerabilidad está corregida en la versión 1.4.dev.
CPE cpe:2.3:a:flatpress:flatpress:*:*:*:*:*:*:*:*
References () https://github.com/flatpressblog/flatpress/commit/a81c968f51f134b5e5f9bbe208aa12f4fbc329df - () https://github.com/flatpressblog/flatpress/commit/a81c968f51f134b5e5f9bbe208aa12f4fbc329df - Patch
References () https://huntr.com/bounties/b30ef7b0-74ea-4cac-adc4-1cc8a5cb559e - () https://huntr.com/bounties/b30ef7b0-74ea-4cac-adc4-1cc8a5cb559e - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-06-24 14:38


NVD link : CVE-2024-9847

Mitre link : CVE-2024-9847

CVE.ORG link : CVE-2024-9847


JSON object : View

Products Affected

flatpress

  • flatpress
CWE
CWE-352

Cross-Site Request Forgery (CSRF)