Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2022-23330
Disclosure Date: February 04, 2022 (last updated October 07, 2023)
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package.
0
Attacker Value
Unknown
CVE-2021-46114
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46118
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46116
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46115
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46117
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-45808
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
0
Attacker Value
Unknown
CVE-2021-45807
Disclosure Date: January 13, 2022 (last updated October 07, 2023)
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
0
Attacker Value
Unknown
CVE-2021-45806
Disclosure Date: January 13, 2022 (last updated February 23, 2025)
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
0