PT-2024-24533 · Jpress · Jpress

Rootlili

·

Published

2024-04-25

·

Updated

2024-08-23

·

CVE-2024-32358

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jpress version 5.1.0
Description An issue in the custom plug-in module function allows a remote attacker to execute arbitrary code via a crafted script. This is a distinct issue from other known vulnerabilities.
Recommendations For Jpress version 5.1.0, consider disabling the custom plug-in module function as a temporary workaround until a patch is available. Restrict access to this function to minimize the risk of exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-32358

Affected Products

Jpress