Critical Vulnerability in jPress Affects Unknown Functionality
CVE-2024-8304
4.9MEDIUM
Key Information
- Vendor
- jpress
- Status
- Jpress
- Vendor
- CVE Published:
- 29 August 2024
Summary
A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template Module Handler. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Version(s)
jpress = 5.1.0
jpress = 5.1.1
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Risk change from: null to: 4.7 - (MEDIUM)
VulDB entry last update
Vulnerability Reserved.
VulDB entry created
Advisory disclosed
Vulnerability published.
Collectors
NVD DatabaseMitre Database
Credit
microvorld (VulDB User)