CVE-2022-41417 Information

Description

BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with iles\ prefix under ~/App_Data/.

Reference

https://gist.github.com/tree-chtsec/22a0a531ea188fd5b76fe11d32f41e95 https://github.com/BlogEngine/BlogEngine.NET/commit/7f927567db94462ffd37e128c0a53c11c1f81a8d

Share on: