CRITICAL 9.8 NuGet
Blogifier does not properly restrict APIs
GHSA-qcx4-gfh8-w5p5 · CVE-2019-12277
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname.
The issue is patched in the 2.4 branch, but 2.5.5 is the lowest available patched version on https://www.nuget.org/packages/Blogifier.Core.
Ready to move
Start Securing
Free, no credit card | First findings in minutes