PT-2026-6062 · Unknown · Bolo-Blog Bolo-Solo

Maoqiu

·

Publicado

2026-02-03

·

Atualizado

2026-03-03

·

CVE-2026-1810

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bolo-blog bolo-solo versions prior to 2.6.5
Description A path traversal issue exists in the ZIP File Handler component of bolo-blog bolo-solo. The issue is located in the unpackFilteredZip function within the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file. Manipulating the File argument can lead to path traversal, and the attack can be carried out remotely. The exploit is publicly available. The project was notified of the issue but has not yet responded.
Recommendations Update bolo-blog bolo-solo to version 2.6.5 or later. As a temporary workaround, restrict access to the unpackFilteredZip function until a patch is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1810

Produtos afetados

Bolo-Blog Bolo-Solo