A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version 1.4.dev.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/flatpressblog/flatpress/commit/f364391085334a7eae02aa2320edd6de7466ec85 | Patch | 
| https://huntr.com/bounties/a993a05f-be50-4983-a44a-3bbff1ec00db | Third Party Advisory | 
Configurations
                    History
                    24 Jun 2025, 14:37
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.4 | 
| References | () https://github.com/flatpressblog/flatpress/commit/f364391085334a7eae02aa2320edd6de7466ec85 - Patch | |
| References | () https://huntr.com/bounties/a993a05f-be50-4983-a44a-3bbff1ec00db - Third Party Advisory | |
| First Time | Flatpress Flatpress flatpress | |
| CPE | cpe:2.3:a:flatpress:flatpress:*:*:*:*:*:*:*:* | 
20 Mar 2025, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-03-20 10:15
Updated : 2025-06-24 14:37
NVD link : CVE-2024-9699
Mitre link : CVE-2024-9699
CVE.ORG link : CVE-2024-9699
JSON object : View
Products Affected
                flatpress
- flatpress
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
