Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-41290 PoC — FlatPress 安全漏洞

Source
Associated Vulnerability
Title:FlatPress 安全漏洞 (CVE-2024-41290)
Description:FlatPress是FlatPress社区的一个基于Php无需数据库支持的博客建站系统。 FlatPress v1.3.1版本存在安全漏洞,该漏洞源于使用不安全的方法通过cookie的组件存储身份验证数据。
Description
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data
Readme
# CVE-2024-41290
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to  store authentication data

Additional Information:

FlatPress CMS version 1.3.1 insecurely stores authentication-related data, including usernames and hashed passwords, directly in client-side cookies. This practice exposes sensitive information to potential unauthorized access and manipulation by attackers.

Vendor of Product:

Insecure Storage of Authentication Data in Cookies

Affected Product Code Base:

FlatPress CMS version 1.3.1 - 1.3

Affected Component:

Cookie

Impact:

Usernames and hashed passwords are exposed in client-side cookies, which can be accessed or modified by unauthorized parties.

If an attacker gains access to these cookies, they can potentially impersonate users or decrypt hashed passwords offline

Discoverer:

Parag Bagul
File Snapshot

[4.0K] /data/pocs/aa2502736b37c9cd435cd6339ed20997411452e3 ├── [129K] poc_cookie.png └── [ 844] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.