CVE-2021-46118: Code Injection
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46118?
CVE-2021-46118 has a severity level that allows for remote code execution, posing a significant risk to affected systems.
How do I fix CVE-2021-46118?
To fix CVE-2021-46118, update jpress to the latest version or apply security patches provided by the vendor.
What systems are affected by CVE-2021-46118?
CVE-2021-46118 specifically affects jpress version 4.2.0.
What kind of attack does CVE-2021-46118 allow?
CVE-2021-46118 allows attackers to perform remote code execution through the manipulation of email templates in the admin panel.
Is my data at risk due to CVE-2021-46118?
Yes, if you are using jpress 4.2.0, your data may be at risk of being compromised due to the remote code execution vulnerability.