Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6840 | A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version 1.4.dev. |
Tue, 24 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flatpress
Flatpress flatpress |
|
| CPEs | cpe:2.3:a:flatpress:flatpress:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flatpress
Flatpress flatpress |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version 1.4.dev. | |
| Title | Cross-Site Scripting (XSS) in flatpressblog/flatpress | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:34:52.446Z
Reserved: 2024-10-09T17:22:02.316Z
Link: CVE-2024-9699
Updated: 2025-03-20T17:50:18.000Z
Status : Analyzed
Published: 2025-03-20T10:15:49.797
Modified: 2025-06-24T14:37:51.640
Link: CVE-2024-9699
No data.
OpenCVE Enrichment
No data.
EUVD