Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2022-23330

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package.
Attacker Value
Unknown

CVE-2021-46114

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46118

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46116

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46115

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-46117

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Attacker Value
Unknown

CVE-2021-45808

Disclosure Date: January 19, 2022 (last updated February 23, 2025)
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
Attacker Value
Unknown

CVE-2021-45807

Disclosure Date: January 13, 2022 (last updated October 07, 2023)
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
Attacker Value
Unknown

CVE-2021-45806

Disclosure Date: January 13, 2022 (last updated February 23, 2025)
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.