CVE-2024-50919: Code Injection
Published Nov 18, 2024
·Updated
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
Affected Software
3 affected components
jpress Jpress<5.1.1
All of the following
jpress Jpress<=5.1.1
Microsoft Windows
Event History
Nov 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-50919?
CVE-2024-50919 has a high severity due to its potential for arbitrary command execution.
2
How do I fix CVE-2024-50919?
To fix CVE-2024-50919, update Jpress to version 5.1.1 or later, which addresses the arbitrary file upload vulnerability.
3
What platforms are affected by CVE-2024-50919?
CVE-2024-50919 affects the Windows platform specifically.
4
What types of files can be uploaded due to CVE-2024-50919?
CVE-2024-50919 allows the upload of non-standard file formats such as .jsp.
5
What are the risks associated with CVE-2024-50919?
The risks associated with CVE-2024-50919 include unauthorized command execution and potential system compromise.