PT-2026-6063 · Bolo Blog+1 · Bolo-Blog+1

Maoqiu

·

Publicado

2026-02-03

·

Atualizado

2026-03-03

·

CVE-2026-1811

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bolo-blog bolo-solo versions up to 2.6.4
Description A path traversal issue exists in the Filename Handler component of bolo-blog bolo-solo. The issue is located in the importFromMarkdown function within the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java. Manipulation of the File argument can lead to path traversal, potentially allowing remote exploitation. The exploit has been published.
Recommendations Versions prior to 2.6.4 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1811

Produtos afetados

Bolo-Blog
Bolo-Solo