Описание
Blogifier does not properly restrict APIs
Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname.
The issue is patched in the 2.4 branch, but 2.5.5 is the lowest available patched version on https://www.nuget.org/packages/Blogifier.Core.
Пакеты
Наименование
Blogifier.Core
nuget
Затронутые версииВерсия исправления
< 2.4
2.5.5
Связанные уязвимости
CVSS3: 9.8
nvd
больше 6 лет назад
Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname.