CVE-2024-33210

MEDIUM

Flatpress 1.3 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-33210. PoCs published by paragbagul111.

AI-analyzed exploit summary The repository provides a functional proof-of-concept for a reflected XSS vulnerability in Flatpress 1.3, demonstrating how an attacker can inject malicious scripts via a crafted URL parameter. The PoC includes a specific payload and steps to trigger the vulnerability.

Description

A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.

Exploits (1)

nomisec WORKING POC
by paragbagul111 · poc
https://github.com/paragbagul111/CVE-2024-33210

The repository provides a functional proof-of-concept for a reflected XSS vulnerability in Flatpress 1.3, demonstrating how an attacker can inject malicious scripts via a crafted URL parameter. The PoC includes a specific payload and steps to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Flatpress v1.3
No auth needed
Prerequisites: Access to the target Flatpress instance · Ability to craft and send malicious URLs
MITRE ATT&CK
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://github.com/paragbagul111/CVE-2024-33210

Scores

CVSS v3 5.4
EPSS 0.0060
EPSS Percentile 44.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
flatpress/flatpress 1.3
Published Oct 02, 2024
Tracked Since Feb 18, 2026