CVE-2019-9845
16.04.2019, 18:29
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.Enginsight
Vendor | Product | Version |
---|---|---|
miniblog.core_project | miniblog.core | 𝑥 ≤ 2019-01-16 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References