CVE-2019-10717 is a directory traversal vulnerability affecting BlogEngine.NET version 3.3.7.0, specifically within the /api/filemanager component via the 'path' parameter. This high-severity flaw (CVSS 7.1) allows an authenticated attacker to read or modify arbitrary files on the server with low attack complexity. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists for detecting Local File Inclusion, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.7.0CPE matchmatch criteria | cpe:2.3:a:dotnetblogengine:blogengine.net:3.3.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.