PT-2026-6063 · Bolo Blog+1 · Bolo-Blog+1
Maoqiu
·
Publicado
2026-02-03
·
Atualizado
2026-03-03
·
CVE-2026-1811
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bolo-blog bolo-solo versions up to 2.6.4
Description
A path traversal issue exists in the Filename Handler component of bolo-blog bolo-solo. The issue is located in the
importFromMarkdown function within the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java. Manipulation of the File argument can lead to path traversal, potentially allowing remote exploitation. The exploit has been published.Recommendations
Versions prior to 2.6.4 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bolo-Blog
Bolo-Solo