Record summary

CVE-2021-41432 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMFlatPress 1.2.1 - Stored Cross-Site ScriptingCVSS 5.4

FlatPress 1.2.1 contains a stored cross-site scripting vulnerability that allows for arbitrary execution of JavaScript commands through blog content. An attacker can possibly steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the application, leading to potential data theft, session hijacking, or defacement of the website.

Remediation

Upgrade to the latest version of FlatPress (1.2.2) or apply the provided patch to fix the XSS vulnerability.

WeaknessesCWE-79
Authorsarafatansari
Template tagscve2021cveflatpressxssauthenticatedossintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:flatpress:flatpress:1.2.1:*:*:*:*:*:*:*
Shodan: http.html:"Flatpress"
Shodan: http.html:"flatpress"
Shodan: http.favicon.hash:-1189292869
FOFA: body="flatpress"
FOFA: icon_hash=-1189292869

Source: ProjectDiscovery

References

2