CVE-2024-32358: Code Injection
Published Apr 25, 2024
·Updated
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033.
Affected Software
2 affected components
jpress Jpress=5.1.0
jpress Jpress=5.1.0
Event History
Apr 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32358?
CVE-2024-32358 is classified as a high-severity vulnerability allowing remote code execution.
2
How do I fix CVE-2024-32358?
To fix CVE-2024-32358, update Jpress to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2024-32358?
CVE-2024-32358 affects users running Jpress version 5.1.0.
4
What type of vulnerability is CVE-2024-32358?
CVE-2024-32358 is a remote code execution vulnerability in the custom plug-in module function.
5
Can CVE-2024-32358 affect my web application?
Yes, if your web application uses Jpress 5.1.0, it is at risk from CVE-2024-32358.