Posted by Andrey Stoykov on Sep 22
# Exploit Title: Stored HTML Injection – flatpressv1.4.1
# Date: 09/2025
# Exploit Author: Andrey Stoykov
# Version: 1.4.1
# Tested on: Debian 12
# Blog:
https://msecureltd.blogspot.com/2025/09/friday-fun-pentest-series-41-stored.html
Stored HTML Injection:
Steps to Reproduce:
– Login with admin user and visit “Main” > “New Entry” > “Write Entry” and
in the description enter the payload “[html]<div…
– Read More – Full Disclosure



