{"id":"GHSA-958r-g534-ccmr","summary":"MadsKristensen.AspNetCore.Miniblog subject to Improper Input Validation","details":"madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.","aliases":["CVE-2019-9845"],"modified":"2024-02-19T05:32:27.163063Z","published":"2019-07-05T21:11:13Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:27:35Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9845"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-958r-g534-ccmr"},{"type":"PACKAGE","url":"https://github.com/madskristensen/Miniblog.Core"},{"type":"WEB","url":"https://github.com/madskristensen/Miniblog.Core/blob/master/src/Controllers/BlogController.cs#L142"},{"type":"WEB","url":"https://rastating.github.io/miniblog-remote-code-execution"}],"affected":[{"package":{"name":"MadsKristensen.AspNetCore.Miniblog","ecosystem":"NuGet","purl":"pkg:nuget/MadsKristensen.AspNetCore.Miniblog"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0.3"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-958r-g534-ccmr/GHSA-958r-g534-ccmr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}