Vulnerability Description
FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flatpress | Flatpress | 1.3 |
Related Weaknesses (CWE)
References
- https://github.com/paragbagul111/CVE-2024-33209ExploitThird Party Advisory
FAQ
What is CVE-2024-33209?
CVE-2024-33209 is a vulnerability with a CVSS score of 5.4 (MEDIUM). FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the contex...
How severe is CVE-2024-33209?
CVE-2024-33209 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-33209?
Check the references section above for vendor advisories and patch information. Affected products include: Flatpress Flatpress.