Metrics
Affected Vendors & Products
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 09 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jpress
Jpress jpress |
|
| CPEs | cpe:2.3:a:jpress:jpress:5.1.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Jpress
Jpress jpress |
|
| Metrics |
ssvc
|
Mon, 09 Dec 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-09T00:00:12.081Z
Updated: 2024-12-09T17:59:35.372Z
Reserved: 2024-12-08T08:32:45.861Z
Link: CVE-2024-12348
Updated: 2024-12-09T17:40:41.158Z
Status : Analyzed
Published: 2024-12-09T01:15:05.603
Modified: 2025-06-04T19:13:14.097
Link: CVE-2024-12348
No data.