BlogEngine / BlogEngine.NET

Multi-User ASP.NET Blogging Application
https://blogengine.io/
958 stars 547 forks source link

Fixed security issues #260

Closed tree-chtsec closed 1 year ago

tree-chtsec commented 1 year ago

I fix some issues known as CVE-2022-41417 & CVE-2022-41418.

I haven't had any remediation about the arbitrary folder creation inside ~/App_Data/files/. Maybe it's feature...

Here is the PoC screenshot about it. Feel free to comment if any advices. :)

截圖 2022-10-24 下午1 46 54 截圖 2022-10-24 下午1 47 13
rheldt commented 1 year ago

Thank you!

farzindev commented 1 year ago

@tree-chtsec if you have time, please contact us, we have a technical question, thanks.