THREAT OPS › Threat News › Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read
Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read
<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS v1.0.0-alpha.3 contains a stored arbitrary expression<br /> injection vulnerability in the Entries ExpressionsDirective. An<br /> authenticated remote attacker with sufficient privileges to create or<br /> modify entries can persist arbitrary expression syntax within an entry<br /> field. When the affected field is subsequently
Original source: https://seclists.org/fulldisclosure/2026/Sep/20