Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm9p-f2cp-2w64

Опубликовано: 27 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

EPSS

Процентиль: 79%
0.01283
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

EPSS

Процентиль: 79%
0.01283
Низкий

Дефекты

CWE-94