CVE-2019-12277

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/05/2019
Last modified:
24/08/2020

Description

Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:blogifier:blogifier:2.3:*:*:*:*:*:*:*