Vulnerability Description
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is unrelated to the attack vector for CVE-2024-32358.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jpress | Jpress | <= 5.1.1 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/69.htmlNot Applicable
- https://github.com/JPressProjects/jpress/issues/188ExploitIssue TrackingVendor Advisory
- https://github.com/lazy-forever/CVE-Reference/tree/main/2024/43033ExploitThird Party Advisory
FAQ
What is CVE-2024-43033?
CVE-2024-43033 is a vulnerability with a CVSS score of 8.8 (HIGH). JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.co...
How severe is CVE-2024-43033?
CVE-2024-43033 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43033?
Check the references section above for vendor advisories and patch information. Affected products include: Jpress Jpress, Microsoft Windows.