PT-2024-30264 · Jpress · Jpress

·

CVE-2024-43033

·

Published

2024-08-21

·

Updated

2024-08-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JPress versions through 5.1.1
Description The issue is an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. This vulnerability allows for potential code execution on the server.
Recommendations For JPress versions through 5.1.1, consider disabling the upload function in AttachmentController until a patch is available to prevent arbitrary file uploads and potential code execution. Restrict access to the AttachmentController to minimize the risk of exploitation. Avoid using the ::$DATA technique in file uploads to the affected AttachmentController until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43033

Affected Products

Jpress