Flatpress < 1.3 - Path Traversal
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
FlatPressPoC 已收录
CVSS9.8EPSS 75.9%
共找到 3 条公开漏洞记录
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
FlatPress 1.2.1 contains a stored cross-site scripting vulnerability that allows for arbitrary execution of JavaScript commands through blog content. An attacker can possibly steal cookie-based authentication credentials and launch other attacks.