Web / CMS

Cross-Site Scripting (XSS)

Flatpress v1.2.1 reflected XSS via page parameter at /flatpress/admin.php

Reflected XSS on page parameter in Flatpress 1.2.1 Page parameter does not sanitize input properly and reflect as it leads to reflected XSS attacks.

5.4
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS56
PUBLISHED
2023-01-16
CVE IDs
CVE-2022-40047
VENDORS
Flatpress
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
FlatPress v1.2.1
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Reflected XSS on page parameter in Flatpress 1.2.1

Page parameter does not sanitize input properly and reflect as it leads to reflected XSS attacks.

Vulnerability details

Vulnerability details

CVE-2022-40047
CWE-79
Medium | 5.4

Reflected XSS on page parameter in Flatpress 1.2.1 Page parameter does not sanitize input properly and reflect as it leads to reflected XSS attacks.

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2022-07-27 Reported On

2022-09-28 Made Public On

Fixed On: Fix in Progress

Credits

Sandeep Wawdane