Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2024-12348

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2024-11971

Disclosure Date: November 28, 2024 (last updated December 21, 2024)
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-8304

Disclosure Date: August 29, 2024 (last updated September 20, 2024)
A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template Module Handler. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-23330

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package.
Attacker Value
Unknown

CVE-2021-46114

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46118

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46116

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46115

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46117

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-45808

Disclosure Date: January 19, 2022 (last updated February 23, 2025)
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.