CVE-2024-8304: jpress Template Module edit path traversal
Published Aug 29, 2024
·Updated
A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template Module Handler. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
jpress Jpress<=5.1.1
Event History
Aug 29, 2024
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Apr 25, 56770
Event
via FIRST·04:57 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-8304?
CVE-2024-8304 is classified as a critical severity vulnerability.
2
How do I fix CVE-2024-8304?
To fix CVE-2024-8304, you should upgrade jpress to version 5.1.2 or later.
3
What type of vulnerability is CVE-2024-8304?
CVE-2024-8304 is a path traversal vulnerability found in the Template Module Handler.
4
Which versions of jpress are affected by CVE-2024-8304?
CVE-2024-8304 affects jpress versions up to and including 5.1.1.
5
What component is impacted by CVE-2024-8304?
The impacted component in CVE-2024-8304 is the Template Module Handler located at /admin/template/edit.