vendor:
FlatPress
by:
Ahmet Ümit BAYRAM
6.1
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: FlatPress
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE:
CPE: a:flatpress:flatpress:1.3
Platforms Tested: MacOS
2024
FlatPress v1.3 – Remote Command Execution
FlatPress v1.3 allows remote attackers to execute arbitrary commands via uploading a crafted PHP file. An attacker can exploit this vulnerability by uploading a malicious PHP file and then accessing it to execute arbitrary commands.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict file upload capabilities to only allow specific file types and conduct proper input validation.