jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
References
Link Resource
http://jpress.com Product Vendor Advisory
https://github.com/JPressProjects/jpress Product Third Party Advisory
https://github.com/JPressProjects/jpress/issues/173 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-01-19T12:51:44

Updated: 2022-01-19T12:51:44

Reserved: 2021-12-27T00:00:00


Link: CVE-2021-45808

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-19T13:15:07.920

Modified: 2022-01-25T16:29:47.783


Link: CVE-2021-45808

JSON object: View

cve-icon Redhat Information

No data.

CWE