CVE-2024-9699
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 79
Summary
CVE-2024-9699: A newly discovered vulnerability affects the latest version of FlatPress CMS admin panel. The flaw lies in the file upload functionality, enabling attackers to disguise JavaScript payloads as filenames. Successful exploitation can result in Cross-Site Scripting (XSS) attacks, potentially harming other users. The vulnerability is resolved in the upcoming version 1.4.dev.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.