Learn about CVE-2017-1000428 affecting flatCore-CMS 1.4.6. Understand the XSS vulnerabilities, impacts, and mitigation steps to secure your system.
flatCore-CMS version 1.4.6 is vulnerable to reflected cross-site scripting (XSS) and stored XSS attacks.
Understanding CVE-2017-1000428
flatCore-CMS 1.4.6 has security vulnerabilities that can lead to XSS attacks.
What is CVE-2017-1000428?
The flatCore-CMS version 1.4.6 contains a security flaw in the user_management.php file, making it susceptible to reflected cross-site scripting (XSS) due to the use of $_SERVER['PHP_SELF'] in link creation. Additionally, the admin log panel is at risk of stored XSS attacks if a malformed User-Agent string is specified.
The Impact of CVE-2017-1000428
Technical Details of CVE-2017-1000428
flatCore-CMS 1.4.6 vulnerability details.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your system from CVE-2017-1000428.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates