FlatPress 1.2.1 contains a stored cross-site scripting vulnerability that allows for arbitrary execution of JavaScript commands through blog content. An attacker can steal cookie-based authentication credentials and launch other attacks. Note: this is similar to CVE-2021-41432, however this attack uses the "page" parameter.
id: flatpress-xss
info:
name: FlatPress 1.2.1 - Stored Cross-Site Scripting
author: arafatansar
...