CVE-2021-46115: Malicious File Upload
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin.TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46115?
CVE-2021-46115 is a vulnerability in jpress 4.2.0 that allows remote code execution (RCE) via io.jpress.web.admin._TemplateController#doUploadFile.
How does CVE-2021-46115 affect jpress 4.2.0?
CVE-2021-46115 affects jpress 4.2.0 by allowing attackers to upload templates and inject malicious code through the admin panel.
What is the severity of CVE-2021-46115?
CVE-2021-46115 has a severity rating of 7.2 (high).
How can I fix CVE-2021-46115?
To fix CVE-2021-46115, it is recommended to upgrade jpress to a version that is not affected by this vulnerability.
Is there any additional information available about CVE-2021-46115?
Yes, you can find additional information about CVE-2021-46115 on the JPress GitHub repository and the JPress issue tracker.