CVE-2021-45808High· 8.8▾ Twilightjpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
jpress = 4.2.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-46116High· 7.2jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall
CVE-2021-46115High· 7.2jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile
CVE-2021-46114High· 8.8jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail
CVE-2021-46118High· 7.2jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail
CVE-2021-46117High· 7.2jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail
CVE-2021-45807Critical· 9.8jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.