5.4
CVSSv3

CVE-2021-41432

Published: 23/06/2022 Updated: 29/06/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

flatpress flatpress 1.2.1

Github Repositories

🎯 List of publicly disclosed application vulnerabilities that I found and reported.

CVE-References 🎯 CVE IDs CVE-2021-37413 : Authentication Bypass in CMS provided by GRANDCOM, sro CVE-2021-41432 : Stored XSS in the Blog Content in FlatPress 121 CVE-2021-41433 : Authentication Bypass in Resumes Management by EGavilan Media CVE-2021-41434 : Stored XSS in Expense Management System by EGavilan Media 📭 Unresolved Vulnerabilities Nothing to be found h