Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk1OHItZzUzNC1jY21y
MadsKristensen.AspNetCore.Miniblog subject to Improper Input Validation
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.
Permalink: https://github.com/advisories/GHSA-958r-g534-ccmrJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk1OHItZzUzNC1jY21y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 5 years ago
Updated: almost 2 years ago
CVSS Score: 9.8
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Percentage: 0.00607
EPSS Percentile: 0.78862
Identifiers: GHSA-958r-g534-ccmr, CVE-2019-9845
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-9845
- https://github.com/advisories/GHSA-958r-g534-ccmr
- https://github.com/madskristensen/Miniblog.Core/blob/master/src/Controllers/BlogController.cs#L142
- https://rastating.github.io/miniblog-remote-code-execution/
Blast Radius: 1.0
Affected Packages
nuget:MadsKristensen.AspNetCore.Miniblog
Dependent packages: 0Dependent repositories: 0
Downloads: 14,393 total
Affected Version Ranges: <= 1.0.3
No known fixed version
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3