An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://www.wolai.com/catr00t/2LujDzjjcrAjUYpWtcusXD | permissions required |
https://gist.github.com/rootlili/a6b6c89591f4773857ae81b7ca5898bc | third party advisory |
https://github.com/JPressProjects/jpress/releases/tag/v5.1.0 | release notes |
https://gitee.com/JPressProjects/jpress/releases/tag/v5.1.0 | release notes |
https://www.jpress.cn/download | product |