CVE-2024-4023

Source
https://cve.org/CVERecord?id=CVE-2024-4023
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-4023.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-4023
Published
2025-03-20T10:09:54.666Z
Modified
2026-07-15T01:49:00.675845723Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
Summary
Stored XSS in flatpressblog/flatpress
Details

A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a file with a .xsig extension and directly accesses this file, the server responds with a Content-type of application/octet-stream, leading to the file being processed as an HTML file. This allows an attacker to execute arbitrary JavaScript code, which can be used to steal user cookies, perform HTTP requests, and access content of the same origin.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/4xxx/CVE-2024-4023.json",
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/flatpressblog/flatpress

Affected ranges

Type
GIT
Repo
https://github.com/flatpressblog/flatpress
Events
Database specific
{
    "cpe": "cpe:2.3:a:flatpress:flatpress:1.3:*:*:*:*:*:*:*",
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.3"
        },
        {
            "last_affected": "1.3"
        }
    ]
}

Affected versions

1.*
1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-4023.json"