CVE-2024-9699: Cross-Site Scripting (XSS) in flatpressblog/flatpress
A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version 1.4.dev.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9699?
CVE-2024-9699 has a high severity due to its potential to facilitate Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-9699?
To fix CVE-2024-9699, update the FlatPress CMS to the latest version that addresses this vulnerability.
What versions of FlatPress CMS are affected by CVE-2024-9699?
CVE-2024-9699 affects FlatPress CMS versions prior to 1.4.dev.
What type of attack does CVE-2024-9699 enable?
CVE-2024-9699 enables Cross-Site Scripting (XSS) attacks through malicious file uploads.
Who is vulnerable to CVE-2024-9699?
Any user of the FlatPress CMS admin panel who allows file uploads may be vulnerable to CVE-2024-9699.