PT-2022-12576 · Jpress · Jpress

Published

2022-01-26

·

Updated

2022-02-02

·

CVE-2021-46117

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jpress version 4.2.0
Description The issue allows for remote code execution via the io.jpress.module.page.PageNotifyKit#doSendEmail function. This is possible because the admin panel provides a function that enables attackers to edit email templates and inject malicious code.
Recommendations For jpress version 4.2.0, consider disabling the io.jpress.module.page.PageNotifyKit#doSendEmail function until a patch is available to prevent remote code execution. Restrict access to the admin panel to minimize the risk of exploitation. Avoid using the email template editing function in the admin panel until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46117

Affected Products

Jpress