High severity8.8NVD Advisory· Published Aug 22, 2024· Updated Jun 17, 2026
CVE-2024-43033
CVE-2024-43033
Description
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is unrelated to the attack vector for CVE-2024-32358.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/JPressProjects/jpress/issues/188nvdExploitIssue TrackingVendor Advisory
- github.com/lazy-forever/CVE-Reference/tree/main/2024/43033nvdExploitThird Party Advisory
- cwe.mitre.org/data/definitions/69.htmlnvdNot Applicable
News mentions
0No linked articles in our index yet.