PT-2026-27207 · Blinko · Blinko
Tx1Ee
·
Published
2026-03-23
·
Updated
2026-03-23
·
CVE-2026-23484
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Blinko versions prior to 1.8.3
Description
The
fileName parameter in Blinko is not properly filtered, which allows for path traversal. This enables unauthorized writing of files to any location within the file system. The affected interface only requires standard user authentication (authProcedure) and does not enforce super administrator authentication (superAdminAuthMiddleware).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blinko