CVE-2023-33404
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
CVSS9.8EPSS 84.3%
共找到 3 条公开漏洞记录
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect
BlogEngine.NET 3.3.7.0 allows /api/filemanager local file inclusion via the path parameter