CVE-2024-9699

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 79

Summary

CVE-2024-9699: A newly discovered vulnerability affects the latest version of FlatPress CMS admin panel. The flaw lies in the file upload functionality, enabling attackers to disguise JavaScript payloads as filenames. Successful exploitation can result in Cross-Site Scripting (XSS) attacks, potentially harming other users. The vulnerability is resolved in the upcoming version 1.4.dev.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share