Skip to content

Conversation

@tree-chtsec
Copy link
Contributor

I fix some issues known as CVE-2022-41417 & CVE-2022-41418.

I haven't had any remediation about the arbitrary folder creation inside ~/App_Data/files/. Maybe it's feature...

Here is the PoC screenshot about it. Feel free to comment if any advices. :)
截圖 2022-10-24 下午1 46 54
截圖 2022-10-24 下午1 47 13

But GetDirectory() will create folder if not exists by design. The
problem exists in ~/App_Data/Files/<here> despite this fix.
@rheldt
Copy link

rheldt commented Jan 11, 2023

Thank you!

@farzindev farzindev merged commit 9a37bd1 into BlogEngine:master Jan 12, 2023
@farzindev
Copy link
Member

@tree-chtsec if you have time, please contact us, we have a technical question, thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants