vendor:
Flatpress Add Blog
by:
Alperen Ergel
4.8
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Flatpress Add Blog
Affected Version From: 1.0.3
Affected Version To: 1.0.3
Patch Exists: YES
Related CWE: CVE-2020-35241
CPE: a:flatpress:flatpress:1.0.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 / XAMPP
2020
Flatpress Add Blog 1.0.3 – Persistent Cross-Site Scripting
Flatpress Add Blog 1.0.3 is vulnerable to persistent cross-site scripting. An attacker can inject malicious JavaScript code into the content parameter of the POST request to the admin.php page. This code will be executed when the page is loaded by an authenticated user.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of the software.