CVE-2024-25411: XSS
Published Sep 27, 2024
·Updated
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php.
Affected Software
2 affected components
flatpress flatpress
flatpress flatpress<1.3
Event History
Sep 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25411?
The severity of CVE-2024-25411 is categorized as high due to its potential impact on user data and security.
2
How do I fix CVE-2024-25411?
To fix CVE-2024-25411, update to the latest version of Flatpress where the XSS vulnerability has been patched.
3
What type of vulnerability is CVE-2024-25411?
CVE-2024-25411 is a cross-site scripting (XSS) vulnerability.
4
Which version of Flatpress is affected by CVE-2024-25411?
CVE-2024-25411 affects Flatpress version 1.3.
5
What can attackers do with CVE-2024-25411?
With CVE-2024-25411, attackers can execute arbitrary web scripts or HTML via injected payloads.