Jpressprojects
Products
1- 9 CVEs
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-12348 | 0.00 | — | 0.00 | Dec 9, 2024 | A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument… | |||
| CVE-2024-11971 | 0.00 | — | 0.00 | Nov 28, 2024 | A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross… | |||
| CVE-2024-50919 | 0.00 | — | 0.01 | Nov 18, 2024 | Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution | |||
| CVE-2024-46468 | 0.00 | — | 0.00 | Oct 11, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in an information disclosure. | |||
| CVE-2024-8304 | 0.00 | — | 0.00 | Aug 29, 2024 | A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template Module Handler. The manipulation leads to path traversal. The attack can be… | |||
| CVE-2024-43033 | 0.00 | — | 0.01 | Aug 22, 2024 | JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is unrelated to the… | |||
| CVE-2024-32358 | 0.00 | — | 0.01 | Apr 25, 2024 | An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033. | |||
| CVE-2019-6278 | 0.00 | — | 0.00 | Jan 14, 2019 | XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option. | |||
| CVE-2018-19170 | 0.00 | — | 0.00 | Nov 11, 2018 | In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter. |
- CVE-2024-12348Dec 9, 2024risk 0.00cvss —epss 0.00
A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument…
- CVE-2024-11971Nov 28, 2024risk 0.00cvss —epss 0.00
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross…
- CVE-2024-50919Nov 18, 2024risk 0.00cvss —epss 0.01
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
- CVE-2024-46468Oct 11, 2024risk 0.00cvss —epss 0.00
A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in an information disclosure.
- CVE-2024-8304Aug 29, 2024risk 0.00cvss —epss 0.00
A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template Module Handler. The manipulation leads to path traversal. The attack can be…
- CVE-2024-43033Aug 22, 2024risk 0.00cvss —epss 0.01
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is unrelated to the…
- CVE-2024-32358Apr 25, 2024risk 0.00cvss —epss 0.01
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033.
- CVE-2019-6278Jan 14, 2019risk 0.00cvss —epss 0.00
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
- CVE-2018-19170Nov 11, 2018risk 0.00cvss —epss 0.00
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter.