jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-01-26T18:50:02

Updated: 2024-08-04T05:02:10.391Z

Reserved: 2022-01-03T00:00:00

Link: CVE-2021-46114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-01-26T19:15:08.290

Modified: 2022-02-03T20:18:09.410

Link: CVE-2021-46114

cve-icon Redhat

No data.