Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Fixed security issues #260

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
farzindev merged 2 commits into BlogEngine:master from tree-chtsec:master
Jan 12, 2023
Merged

Fixed security issues #260

farzindev merged 2 commits into BlogEngine:master from tree-chtsec:master
Jan 12, 2023

Conversation

@tree-chtsec
Copy link
Contributor

@tree-chtsec tree-chtsec commented Oct 24, 2022

I fix some issues known as CVE-2022-41417 & CVE-2022-41418.

I haven't had any remediation about the arbitrary folder creation inside ~/App_Data/files/. Maybe it's feature...

Here is the PoC screenshot about it. Feel free to comment if any advices. :)
截圖 2022年10月24日 下午1 46 54
截圖 2022年10月24日 下午1 47 13

But GetDirectory() will create folder if not exists by design. The
problem exists in ~/App_Data/Files/<here> despite this fix.
Copy link

rheldt commented Jan 11, 2023

Thank you!

@farzindev farzindev merged commit 9a37bd1 into BlogEngine:master Jan 12, 2023
Copy link
Member

@tree-chtsec if you have time, please contact us, we have a technical question, thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /