First published: Thu Feb 16 2023(Updated: )
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flatcore Flatcore | =2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Cross-Site Scripting (XSS) vulnerability in flatCore-CMS is CVE-2021-40555.
The severity of CVE-2021-40555 is medium, with a severity value of 5.4.
CVE-2021-40555 allows attackers to execute arbitrary code by exploiting a Cross-Site Scripting (XSS) vulnerability in the new page creation form's description field.
Version 2.2.15 of flatCore-CMS is affected by CVE-2021-40555.
Yes, you can find the reference for CVE-2021-40555 at this link: https://github.com/flatCore/flatCore-CMS/issues/56