Description
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
References (2)
Core 2
Core References
Patch x_refsource_confirm
https://github.com/flatCore/flatCore-CMS/commit/f1b42b338693a9c240182e76ef2131057f2c2a87
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/flatCore/flatCore-CMS/issues/34
Scores
CVSS v3
6.1
EPSS
0.0022
EPSS Percentile
44.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
flatcore/flatcore
1.4.6
Published
Jun 06, 2017
Tracked Since
Feb 18, 2026