CVE-2024-46468

A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in an information disclosure.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:jpress:jpress:*:*:*:*:*:*:*:*

History

27 May 2025, 19:31

Type Values Removed Values Added
First Time Jpress
Jpress jpress
References () https://gist.github.com/ilikeoyt/b396bbb9ef858105c46e999630e7afbe - () https://gist.github.com/ilikeoyt/b396bbb9ef858105c46e999630e7afbe - Third Party Advisory
References () https://github.com/JPressProjects/jpress/issues/190 - () https://github.com/JPressProjects/jpress/issues/190 - Exploit, Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:jpress:jpress:*:*:*:*:*:*:*:*

15 Oct 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-918

15 Oct 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Server-Side Request Forgery (SSRF) en jpress &lt;= v5.1.1, que puede ser explotada por un atacante para obtener información confidencial, lo que resulta en una divulgación de información.

11 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-11 21:15

Updated : 2025-05-27 19:31


NVD link : CVE-2024-46468

Mitre link : CVE-2024-46468

CVE.ORG link : CVE-2024-46468


JSON object : View

Products Affected

jpress

  • jpress
CWE
CWE-918

Server-Side Request Forgery (SSRF)