A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226109 was assigned to this vulnerability.
References
Link Resource
https://github.com/c3p0ooo-Yiqiyin/mogu_blog_v2/blob/main/README.md Exploit Third Party Advisory
https://github.com/moxi624/mogu_blog_v2/issues/97 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.226109 Permissions Required Third Party Advisory
https://vuldb.com/?id.226109 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulDB

Published: 2023-04-15T12:31:03.981Z

Updated: 2023-10-22T14:14:43.458Z

Reserved: 2023-04-15T09:22:03.992Z


Link: CVE-2023-2101

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-04-15T13:15:45.083

Modified: 2024-05-17T02:22:40.420


Link: CVE-2023-2101

JSON object: View

cve-icon Redhat Information

No data.

CWE