Skip to content

Fixed security issues#260

Merged
farzindev merged 2 commits into
BlogEngine:masterfrom
tree-chtsec:master
Jan 12, 2023
Merged

Fixed security issues#260
farzindev merged 2 commits into
BlogEngine:masterfrom
tree-chtsec:master

Conversation

@tree-chtsec

Copy link
Copy Markdown
Contributor

I fix some issues known as CVE-2022-41417 & CVE-2022-41418.

I haven't had any remediation about the arbitrary folder creation inside ~/App_Data/files/. Maybe it's feature...

Here is the PoC screenshot about it. Feel free to comment if any advices. :)
截圖 2022-10-24 下午1 46 54
截圖 2022-10-24 下午1 47 13

But GetDirectory() will create folder if not exists by design. The
problem exists in ~/App_Data/Files/<here> despite this fix.
@rheldt

rheldt commented Jan 11, 2023

Copy link
Copy Markdown

Thank you!

@farzindev farzindev merged commit 9a37bd1 into BlogEngine:master Jan 12, 2023
@farzindev

Copy link
Copy Markdown
Member

@tree-chtsec if you have time, please contact us, we have a technical question, thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants