CVEbuzz logo
This website displays data collected from external sources, and is not responsible for any aspect of it. Read more...

Security / vulnerability advisories for B3log Wide 1.5.1

Titles listed in dictionary

CPE for product: cpe:2.3:a:b3log:wide:1.5.1:*:*:*:*:*:*:*

Showing 1-1 of 1
Medium damage 7.5
Very easy to exploit
(other affected products) Published: Thu Jul 18 15:15:00 2019 UTC. Last Modified: Mon Aug 24 17:37:00 2020 UTC
CPE matches: cpe:2.3:a:b3log:wide:*:*:*:*:*:*:*:* && versionEndExcluding=1.6.0

Description

b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create a symlink, and then place the symlink into a ZIP archive. An unzip operation leads to read access, and write access (depending on file permissions), to the symlink target. Third, the attacker can import a Git repository that contains a symlink, similarly leading to read and write access.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (CVSSv3)

Type of bug(s)

References