PT-2026-6064 · Bolo Blog+1 · Bolo-Blog+1
Maoqiu
·
Publicado
2026-02-03
·
Atualizado
2026-03-03
·
CVE-2026-1812
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bolo-blog bolo-solo versions up to 2.6.4
Description
A path traversal issue exists due to the manipulation of the
File argument within the importFromCnblogs() function located in the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file of the Filename Handler component. This allows for remote exploitation. The details of the exploit have been publicly disclosed. The project maintainers were notified of the issue but have not yet responded.Recommendations
Versions prior to 2.6.4 should be used. As a temporary workaround, consider restricting access to the
importFromCnblogs() function until a patch is available.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bolo-Blog
Bolo-Solo