First published: Wed Jan 19 2022(Updated: )
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45808 has been categorized as a high-severity vulnerability due to the potential for arbitrary file uploads.
To mitigate CVE-2021-45808, disable unvalidated user registration and restrict file upload permissions.
CVE-2021-45808 can allow attackers to upload malicious files, potentially leading to further exploitation of the server.
CVE-2021-45808 specifically affects jpress version 4.2.0.
Currently, there is no official patch for CVE-2021-45808, so applying mitigations is crucial until a fix is provided.