CVE-2024-41290
HIGHDescription
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.
Is your site exposed to CVE-2024-41290?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| flatpress | flatpress |
References
Other References
Frequently Asked Questions
What is CVE-2024-41290? +
How severe is CVE-2024-41290? +
What products are affected by CVE-2024-41290? +
How do I check if I'm vulnerable to CVE-2024-41290? +
Related Vulnerabilities
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka …
1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel …
A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of …
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some …
A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a file with a `.xsig` …
FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable …