Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2024-11971
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-8304
Disclosure Date: August 29, 2024 (last updated September 20, 2024)
A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template Module Handler. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2022-23330
Disclosure Date: February 04, 2022 (last updated October 07, 2023)
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package.
0
Attacker Value
Unknown
CVE-2021-46114
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46118
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46116
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46115
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-46117
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
0
Attacker Value
Unknown
CVE-2021-45808
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
0
Attacker Value
Unknown
CVE-2021-45807
Disclosure Date: January 13, 2022 (last updated October 07, 2023)
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
0