CVE-2024-33210

MEDIUM

Flatpress - XSS

Title source: rule
STIX 2.1

Description

A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.

Exploits (1)

nomisec WORKING POC
by paragbagul111 · poc
https://github.com/paragbagul111/CVE-2024-33210

Scores

CVSS v3 5.4
EPSS 0.0291
EPSS Percentile 86.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
flatpress/flatpress 1.3
Published Oct 02, 2024
Tracked Since Feb 18, 2026