First published: Wed Jan 26 2022(Updated: )
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46118 has a severity level that allows for remote code execution, posing a significant risk to affected systems.
To fix CVE-2021-46118, update jpress to the latest version or apply security patches provided by the vendor.
CVE-2021-46118 specifically affects jpress version 4.2.0.
CVE-2021-46118 allows attackers to perform remote code execution through the manipulation of email templates in the admin panel.
Yes, if you are using jpress 4.2.0, your data may be at risk of being compromised due to the remote code execution vulnerability.