BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.
References
Link Resource
https://blogengine.io/ Vendor Advisory
https://www.0xlanks.me/blog/cve-2022-25591-advisory/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-13T14:33:56

Updated: 2022-05-13T14:33:56

Reserved: 2022-02-21T00:00:00


Link: CVE-2022-25591

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-13T15:15:08.890

Modified: 2022-05-23T18:50:26.997


Link: CVE-2022-25591

JSON object: View

cve-icon Redhat Information

No data.

CWE