A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.
References
Link Resource
https://blogengine.io/ Product
https://www.0xlanks.me/blog/cve-2022-28921-advisory/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-18T17:11:02

Updated: 2022-05-18T17:11:02

Reserved: 2022-04-11T00:00:00


Link: CVE-2022-28921

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-18T18:15:10.347

Modified: 2022-05-26T12:43:40.763


Link: CVE-2022-28921

JSON object: View

cve-icon Redhat Information

No data.

CWE