PoC Index

CVE-2024-33209

MEDIUM 5.4EPSS 0.8%

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.79% chance of exploitation in the next 30 days, 54th percentile
Published
2024-10-02
Updated
2025-03-14

Proof-of-concept exploits (1)

References

Related