Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://github.com/JPressProjects/jpress | product |
https://github.com/microvorld/CVE-2024/blob/main/jpress.md | third party advisory exploit |
https://gist.github.com/microvorld/516552dcef65acc2d1ab0fb969cd34a3 | third party advisory |