First published: Wed Jan 26 2022(Updated: )
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46115 is a vulnerability in jpress 4.2.0 that allows remote code execution (RCE) via io.jpress.web.admin._TemplateController#doUploadFile.
CVE-2021-46115 affects jpress 4.2.0 by allowing attackers to upload templates and inject malicious code through the admin panel.
CVE-2021-46115 has a severity rating of 7.2 (high).
To fix CVE-2021-46115, it is recommended to upgrade jpress to a version that is not affected by this vulnerability.
Yes, you can find additional information about CVE-2021-46115 on the JPress GitHub repository and the JPress issue tracker.