Stored Cross-Site Scripting Vulnerability in Flatboard Pro
CVE-2025-40723
5.1MEDIUM
What is CVE-2025-40723?
A stored Cross-Site Scripting (XSS) vulnerability exists in Flatboard Pro prior to version 3.2.2. This flaw arises from inadequate validation of user input, specifically through the 'footer_text' and 'announcement' parameters in config.php. Attackers can exploit this vulnerability to inject malicious scripts, which may affect other users by executing these scripts in their browsers, leading to possible data breaches and compromised user accounts.
Affected Version(s)
Flatboard 0 < 3.2.2