Ad

CVE-2026-1813

MEDIUM CVSS 4.0: 5.3 EPSS 0.02%
Updated Feb 04, 2026
Java
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-434 (Unrestricted File Upload (Неограниченная загрузка файлов)), CWE-284 (Improper Access Control (Неправильный контроль доступа))
Vendor Java
Public PoC No

A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Template Handler. The manipulation of the argument File results in unrestricted upload.

It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Attack Parameters

Attack Vector
Network
Атака возможна удалённо
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
None
Нет дополнительных условий
Privileges Required
Low
Нужны базовые права
User Interaction
None
Не нужно действие пользователя

Impact Assessment

Confidentiality
Low
Частичная утечка данных
Integrity
Low
Частичная модификация данных
Availability
Low
Частичное нарушение работы

CVSS Vector v4.0