Stored Cross-Site Scripting Vulnerability in FlatPress by FlatPress Team
CVE-2025-25460

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 February 2025

Summary

A stored Cross-Site Scripting (XSS) vulnerability has been detected in FlatPress version 1.3.1, specifically within the 'Add Entry' functionality. This vulnerability permits authenticated users to inject harmful JavaScript payloads into blog posts. The security risk stems from inadequate input sanitization of the 'TextArea' field when submitting blog entries, which allows the injected scripts to execute in the browsers of users who later view those posts. Ensuring robust input checks is crucial for maintaining the integrity and safety of user-generated content.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.