A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the argument editormd-image-file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://vuldb.com/?id.290232 | technical description vdb entry third party advisory |
https://vuldb.com/?ctiid.290232 | vdb entry signature permissions required |
https://vuldb.com/?submit.469220 | vdb entry third party advisory |
https://github.com/ZHENFENG13/My-Blog/issues/140 | issue tracking exploit |
https://github.com/ZHENFENG13/My-Blog/issues/140#issue-2759813820 | issue tracking exploit |