PT-2026-6063 · Bolo Blog+1 · Bolo-Blog+1
Maoqiu
·
Published
2026-02-03
·
Updated
2026-03-03
·
CVE-2026-1811
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bolo-blog bolo-solo versions up to 2.6.4
Description
A path traversal issue exists in the Filename Handler component of bolo-blog bolo-solo. The issue is located in the
importFromMarkdown function within the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java. Manipulation of the File argument can lead to path traversal, potentially allowing remote exploitation. The exploit has been published.Recommendations
Versions prior to 2.6.4 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bolo-Blog
Bolo-Solo