A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Mon, 24 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-02-24T00:00:00.000Z
Updated: 2025-02-24T16:52:23.129Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25460

Updated: 2025-02-24T16:51:41.927Z

Status : Received
Published: 2025-02-24T16:15:14.873
Modified: 2025-02-24T17:15:13.900
Link: CVE-2025-25460

No data.