CVE-2024-25412: XSS
Published Sep 27, 2024
·Updated
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.
Affected Software
1 affected component
flatpress flatpress<1.3
Event History
Sep 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-25412?
CVE-2024-25412 has a medium severity level due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2024-25412?
To fix CVE-2024-25412, upgrade Flatpress to version 1.3 or later where the vulnerability has been addressed.
3
What is the impact of CVE-2024-25412 on Flatpress?
CVE-2024-25412 allows attackers to execute arbitrary web scripts or HTML, compromising user data and security.
4
Who is affected by CVE-2024-25412?
CVE-2024-25412 affects users of Flatpress versions prior to 1.3 who utilize the email field in the application.
5
Can CVE-2024-25412 be exploited remotely?
Yes, CVE-2024-25412 can be exploited remotely by attackers submitting crafted payloads in the email field.