PT-2026-6064 · Bolo Blog+1 · Bolo-Blog+1
Maoqiu
·
Published
2026-02-03
·
Updated
2026-03-03
·
CVE-2026-1812
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bolo-blog bolo-solo versions up to 2.6.4
Description
A path traversal issue exists due to the manipulation of the
File argument within the importFromCnblogs() function located in the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file of the Filename Handler component. This allows for remote exploitation. The details of the exploit have been publicly disclosed. The project maintainers were notified of the issue but have not yet responded.Recommendations
Versions prior to 2.6.4 should be used. As a temporary workaround, consider restricting access to the
importFromCnblogs() function until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bolo-Blog
Bolo-Solo