PT-2026-6062 · Unknown · Bolo-Blog Bolo-Solo
Maoqiu
·
Published
2026-02-03
·
Updated
2026-03-03
·
CVE-2026-1810
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bolo-blog bolo-solo versions prior to 2.6.5
Description
A path traversal issue exists in the ZIP File Handler component of bolo-blog bolo-solo. The issue is located in the
unpackFilteredZip function within the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file. Manipulating the File argument can lead to path traversal, and the attack can be carried out remotely. The exploit is publicly available. The project was notified of the issue but has not yet responded.Recommendations
Update bolo-blog bolo-solo to version 2.6.5 or later.
As a temporary workaround, restrict access to the
unpackFilteredZip function until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bolo-Blog Bolo-Solo