PT-2023-24332 · Unknown · Blogengine.Net
CVE-2023-33404
·
Publicado
2023-06-26
·
Atualizado
2023-07-05
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BlogEngine.Net versions 3.3.8.0 and earlier
Description
The issue is related to an Unrestricted Upload vulnerability due to insufficient validation on the
UploadControlled.cs file. This allows remote attackers to execute remote code.Recommendations
For versions 3.3.8.0 and earlier, update to a version that includes proper validation for the
UploadControlled.cs file to prevent remote code execution.
As a temporary workaround, consider restricting access to the UploadControlled.cs file until a patch is available.Exploit
Correção
RCE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blogengine.Net