CVE-2023-1104: Cross-site Scripting (XSS) - Stored in flatpressblog/flatpress
Published Mar 1, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Affected Software
1 affected component
flatpress flatpress<1.3
Remediation
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1104?
CVE-2023-1104 has a severity rating of medium due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2023-1104?
To fix CVE-2023-1104, upgrade Flatpress to version 1.3 or later.
3
What impact does CVE-2023-1104 have on my application?
CVE-2023-1104 can allow attackers to inject malicious scripts, compromising user data and application integrity.
4
Is CVE-2023-1104 exploitable in all configurations?
CVE-2023-1104 may be exploitable depending on the specific configuration and customization of Flatpress.
5
Which versions of Flatpress are affected by CVE-2023-1104?
CVE-2023-1104 affects all versions of Flatpress prior to 1.3.