PT-2026-6064 · Bolo Blog+1 · Bolo-Blog+1

Maoqiu

·

Publicado

2026-02-03

·

Atualizado

2026-03-03

·

CVE-2026-1812

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bolo-blog bolo-solo versions up to 2.6.4
Description A path traversal issue exists due to the manipulation of the File argument within the importFromCnblogs() function located in the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file of the Filename Handler component. This allows for remote exploitation. The details of the exploit have been publicly disclosed. The project maintainers were notified of the issue but have not yet responded.
Recommendations Versions prior to 2.6.4 should be used. As a temporary workaround, consider restricting access to the importFromCnblogs() function until a patch is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1812

Produtos afetados

Bolo-Blog
Bolo-Solo