First published: Thu Jan 13 2022(Updated: )
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for jpress v4.2.0 is CVE-2021-45807.
The severity of CVE-2021-45807 is critical with a CVSS score of 9.8.
The vulnerability in jpress v4.2.0 allows command execution through the io.jpress.web.admin._AddonController::doUploadAndInstall function.
At the moment, there is no official fix available for CVE-2021-45807. It is recommended to update to a patched version once it becomes available or apply any recommended security patches.
More information about jpress v4.2.0 and the vulnerability can be found on the JPress website (http://jpress.com) and the JPress GitHub repository (https://github.com/JPressProjects/jpress).