CVE-2021-46117: Code Injection
Published Jan 26, 2022
·Updated
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Affected Software
1 affected component
jpress Jpress=4.2.0
Event History
Jan 26, 2022
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-46117?
CVE-2021-46117 refers to a vulnerability in jpress 4.2.0 that allows remote code execution.
2
How severe is CVE-2021-46117?
CVE-2021-46117 has a severity score of 7.2, which is categorized as high.
3
What is affected by CVE-2021-46117?
jpress 4.2.0 is affected by CVE-2021-46117.
4
How can an attacker exploit CVE-2021-46117?
An attacker can exploit CVE-2021-46117 by injecting malicious code into the admin panel's email templates.
5
Are there any fixes available for CVE-2021-46117?
As of now, there are no specific fixes available for CVE-2021-46117. It is recommended to update to the latest version of jpress when a fix becomes available.