An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter HTTP request body parameter for the acp interface. The affected parameter accepts malicious client-side script without proper input sanitization. For example, a malicious user can leverage this vulnerability to steal cookies from a victim user and perform a session-hijacking attack, which may then lead to unauthorized access to the site.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-01-15T06:27:45
Updated: 2024-08-03T19:14:09.152Z
Reserved: 2021-01-11T00:00:00
Link: CVE-2021-23838
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-01-15T07:15:14.143
Modified: 2024-11-21T05:51:54.857
Link: CVE-2021-23838
Redhat
No data.