Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-41290 PoC — FlatPress 安全漏洞

Source
Associated Vulnerability
Title: FlatPress 安全漏洞 (CVE-2024-41290)
Description:FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.
Description
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data
Readme
# CVE-2024-41290
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to  store authentication data

Additional Information:

FlatPress CMS version 1.3.1 insecurely stores authentication-related data, including usernames and hashed passwords, directly in client-side cookies. This practice exposes sensitive information to potential unauthorized access and manipulation by attackers.

Vendor of Product:

Insecure Storage of Authentication Data in Cookies

Affected Product Code Base:

FlatPress CMS version 1.3.1 - 1.3

Affected Component:

Cookie

Impact:

Usernames and hashed passwords are exposed in client-side cookies, which can be accessed or modified by unauthorized parties.

If an attacker gains access to these cookies, they can potentially impersonate users or decrypt hashed passwords offline

Discoverer:

Parag Bagul
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →