CVE-2025-44108

A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
Configurations

No configuration.

History

21 May 2025, 20:25

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el panel de administración de Flatpress CMS (versión anterior a la 1.4) a través del componente de subtítulos de la galería. Un atacante con privilegios de administrador puede inyectar un payload de JavaScript maliciosa en el sistema, que posteriormente se almacena de forma persistente.

19 May 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-79
References () https://harish0x.github.io/blog/CVE-2025-44108 - () https://harish0x.github.io/blog/CVE-2025-44108 -

19 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-19 14:15

Updated : 2025-05-21 20:25


NVD link : CVE-2025-44108

Mitre link : CVE-2025-44108

CVE.ORG link : CVE-2025-44108


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')