CVE-2021-46114
jpress
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
- CVSS
- 8.8
- EPSS
- 1.33% 68.2% percentile
- CISA KEV
- Not listed
- Published
- 2022.01.27