FlatPress是FlatPress社区的一个基于Php无需数据库支持的博客建站系统。 FlatPress v1.3版本存在安全漏洞。攻击者利用该漏洞可以将恶意JavaScript代码注入“Add New Entry”部分,从而在受害者的Web浏览器中执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | FlatPress 1.3. is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser. | https://github.com/paragbagul111/CVE-2024-33209 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-45519 | 10.0 CRITICAL | Zimbra Collaboration Server 安全漏洞 |
| CVE-2024-21530 | 4.5 MEDIUM | Cocoon 安全漏洞 |
| CVE-2024-45186 | FileSender 安全漏洞 | |
| CVE-2024-33210 | FlatPress 安全漏洞 | |
| CVE-2024-33662 | Portainer 安全漏洞 | |
| CVE-2024-45960 | Zenario CMS 安全漏洞 | |
| CVE-2024-45962 | October CMS 安全漏洞 | |
| CVE-2024-45964 | Zenario CMS 安全漏洞 | |
| CVE-2024-24117 | Ruijie Networks RG-NBS2009G-P 安全漏洞 | |
| CVE-2024-24122 | Yitu 安全漏洞 | |
| CVE-2024-24116 | Ruijie Networks RG-NBS2009G-P 安全漏洞 | |
| CVE-2024-41290 | FlatPress 安全漏洞 | |
| CVE-2024-46626 | Open Solutions For Education OpenSis-Classic 安全漏洞 |
No comments yet