PT-2021-20122 · Jpress · Jpress

Ghost

·

Published

2021-06-18

·

Updated

2021-06-21

·

CVE-2021-33347

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JPress versions 3.3.0 and below
Description An issue was discovered in the template module and tag management module, leading to XSS vulnerabilities. If a user logs in to the background using a weak password, a storage XSS vulnerability can occur.
Recommendations For JPress versions 3.3.0 and below, consider updating to a newer version to mitigate the risk, although the specific fixed version is not provided. As a temporary workaround, consider restricting access to the template module and tag management module to minimize the risk of exploitation. Additionally, ensure strong passwords are used for background login to reduce the likelihood of storage XSS vulnerability occurrence. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33347

Affected Products

Jpress