Lucene search

K
cveMitreCVE-2022-41417
HistoryJan 18, 2023 - 2:15 p.m.

CVE-2022-41417

2023-01-1814:15:10
CWE-862
mitre
web.nvd.nist.gov
34
blogengine.net
cve-2022-41417
security vulnerability
folder creation

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

57.6%

BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with “files” prefix under ~/App_Data/.

Affected configurations

Nvd
Node
blogengineblogengine.netMatch3.3.8.0
VendorProductVersionCPE
blogengineblogengine.net3.3.8.0cpe:2.3:a:blogengine:blogengine.net:3.3.8.0:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

57.6%

Related for CVE-2022-41417