NA

CVE-2023-33404

Published: 26/06/2023 Updated: 05/07/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and previous versions allows remote malicious users to execute remote code.

Vulnerable Product Search on Vulmon Subscribe to Product

blogengine blogengine.net

Github Repositories

CVE-2023-33404 A user who has EditOwnPosts right on BlogEngineNET CMS (version 3380 and earlier) has the ability to upload a malicious file to a hard-coded location POST request to /api/upload endpoint with "action=video" parameters, as shown in the screenshot below, triggers a file upload process The application, first, checks if the user has EditOwnPosts righ