PT-2026-6062 · Unknown · Bolo-Blog Bolo-Solo
Maoqiu
·
Publicado
2026-02-03
·
Atualizado
2026-03-03
·
CVE-2026-1810
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bolo-blog bolo-solo versions prior to 2.6.5
Description
A path traversal issue exists in the ZIP File Handler component of bolo-blog bolo-solo. The issue is located in the
unpackFilteredZip function within the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file. Manipulating the File argument can lead to path traversal, and the attack can be carried out remotely. The exploit is publicly available. The project was notified of the issue but has not yet responded.Recommendations
Update bolo-blog bolo-solo to version 2.6.5 or later.
As a temporary workaround, restrict access to the
unpackFilteredZip function until a patch is available.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bolo-Blog Bolo-Solo