Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for ..
in a pathname.
The issue is patched in the 2.4
branch, but 2.5.5
is the lowest available patched version on https://www.nuget.org/packages/Blogifier.Core.
{ "nvd_published_at": "2019-05-22T15:29:00Z", "github_reviewed_at": "2025-04-04T19:54:14Z", "github_reviewed": true, "severity": "CRITICAL", "cwe_ids": [ "CWE-22" ] }