Saysky · Sayski Forestblog · CVE-2023-6887
**Name of the Vulnerable Software and Affected Versions**
saysky ForestBlog up to 20220630
**Description**
A critical issue has been found in the Image Upload Handler component, affecting the /admin/upload/img file. The manipulation of the `filename` argument leads to unrestricted upload. This issue can be initiated remotely.
**Recommendations**
For saysky ForestBlog up to 20220630, consider restricting access to the Image Upload Handler component to minimize the risk of exploitation. Avoid using the `filename` argument in the /admin/upload/img file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.