CVE-2021-45806: Code Injection
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-45806?
CVE-2021-45806 is a vulnerability in jpress v4.2.0 admin panel that allows attackers to modify the template and inject malicious code.
What is the severity of CVE-2021-45806?
The severity of CVE-2021-45806 is high with a CVSS score of 8.8.
What software versions are affected by CVE-2021-45806?
jpress v4.2.0 is affected by CVE-2021-45806.
How can an attacker exploit CVE-2021-45806?
An attacker can exploit CVE-2021-45806 by using the function provided by the admin panel to modify the template and inject malicious code.
Are there any references for CVE-2021-45806?
Yes, you can find references for CVE-2021-45806 at the following links: [http://jpress.com](http://jpress.com), [https://github.com/JPressProjects/jpress](https://github.com/JPressProjects/jpress), [https://github.com/JPressProjects/jpress/issues/166](https://github.com/JPressProjects/jpress/issues/166).