Web / CMS
Remote Code Execution
Remote code execution (RCE) via Upload File bypass in Flatpress 1.2.1
Remote code execution (RCE) vulnerability in the Upload File functionality in Flatpress 1.2.1 The application has the functionality to upload images and download them further.
.png)
Overview
Remote code execution (RCE) vulnerability in the Upload File functionality in Flatpress 1.2.1
The application has the functionality to upload images and download them further. The
download functionality is not sandboxed, and it does not have proper security control which can be
bypassed by tricking webserver and uploading dangerous file types which leads to RCE.
Vulnerability details
Remote code execution (RCE) vulnerability in the Upload File functionality in Flatpress 1.2.1 The application has the functionality to upload images and download them further.
Disclosure timeline
2022-05-27 Reported On
2022-09-27 Made Public On
2022-10-01 Fixed On
References
2026-07-09 (NVD record)
Credits
Sandeep Wawdane
















