ZeroHour

CVE-2023-33404

PoC
CVSS 3.1
9.8 critical
EPSS
26%p98
Published
()
Modified
Description

An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.

Vendors
blogengine
Products
blogengine.net
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.