Vulnerability Description
A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version 1.4.dev.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flatpress | Flatpress | < 1.4 |
Related Weaknesses (CWE)
References
- https://github.com/flatpressblog/flatpress/commit/f364391085334a7eae02aa2320edd6Patch
- https://huntr.com/bounties/a993a05f-be50-4983-a44a-3bbff1ec00dbThird Party Advisory
FAQ
What is CVE-2024-9699?
CVE-2024-9699 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead ...
How severe is CVE-2024-9699?
CVE-2024-9699 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9699?
Check the references section above for vendor advisories and patch information. Affected products include: Flatpress Flatpress.