CVE-2024-43033
HIGHDescription
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is unrelated to the attack vector for CVE-2024-32358.
Is your site exposed to CVE-2024-43033?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| jpress | jpress |
| microsoft | windows |
References
Frequently Asked Questions
What is CVE-2024-43033? +
How severe is CVE-2024-43033? +
What products are affected by CVE-2024-43033? +
How do I check if I'm vulnerable to CVE-2024-43033? +
Related Vulnerabilities
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on …
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as …
A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to …
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom …
A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an …
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown …