First published: Tue Feb 15 2022(Updated: )
Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | =1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24588 has been classified as a high severity cross-site scripting (XSS) vulnerability.
To fix CVE-2022-24588, upgrade Flatpress to version 1.2.2 or later which addresses this vulnerability.
CVE-2022-24588 allows an attacker to execute arbitrary JavaScript in the context of a user's browser, potentially leading to data theft.
Yes, CVE-2022-24588 can be exploited remotely due to the nature of the cross-site scripting vulnerability.
If you are using Flatpress version 1.2.1, your installation is vulnerable to CVE-2022-24588.