MadsKristensen.AspNetCore.Miniblog subject to Improper Input Validation
Critical severity
GitHub Reviewed
Published
Jul 5, 2019
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Description
Published to the GitHub Advisory Database
Jul 5, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 11, 2023
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.
References