{"id":"GHSA-qcx4-gfh8-w5p5","summary":"Blogifier does not properly restrict APIs","details":"Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for `..` in a pathname.\n\nThe issue is patched in the `2.4` branch, but `2.5.5` is the lowest available patched version on https://www.nuget.org/packages/Blogifier.Core.","aliases":["CVE-2019-12277"],"modified":"2025-04-04T20:33:49.325167Z","published":"2022-05-24T16:46:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-04-04T19:54:14Z","nvd_published_at":"2019-05-22T15:29:00Z","cwe_ids":["CWE-22"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12277"},{"type":"WEB","url":"https://github.com/blogifierdotnet/Blogifier/commit/3e2ae11f6be8aab82128f223c2916fab5a408be5"},{"type":"PACKAGE","url":"https://github.com/blogifierdotnet/Blogifier"}],"affected":[{"package":{"name":"Blogifier.Core","ecosystem":"NuGet","purl":"pkg:nuget/Blogifier.Core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.5"}]}],"versions":["1.0.0","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4.0","1.4.1-beta","1.4.2-beta","1.4.5","1.4.6-beta","1.4.7-beta","1.4.8-beta"],"database_specific":{"last_known_affected_version_range":"\u003c 2.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qcx4-gfh8-w5p5/GHSA-qcx4-gfh8-w5p5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}