CVE-2021-41432
FlatPress 1.2.1 - Stored Cross-Site Scripting
Record summary
CVE-2021-41432 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMFlatPress 1.2.1 - Stored Cross-Site ScriptingCVSS 5.4
FlatPress 1.2.1 contains a stored cross-site scripting vulnerability that allows for arbitrary execution of JavaScript commands through blog content. An attacker can possibly steal cookie-based authentication credentials and launch other attacks.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the application, leading to potential data theft, session hijacking, or defacement of the website.
Remediation
Upgrade to the latest version of FlatPress (1.2.2) or apply the provided patch to fix the XSS vulnerability.
Source: ProjectDiscovery