CVE-2022-41418 describes a critical arbitrary code execution vulnerability in BlogEngine.NET v3.3.8.0, specifically within the UploadController.cs component, allowing authenticated attackers to execute arbitrary code by uploading a specially crafted PNG file. With a CVSS v3.1 score of 7.2 (HIGH), this vulnerability has a network attack vector and low attack complexity, enabling high impact on confidentiality, integrity, and availability once exploited by a high-privileged user. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, and it has received no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.8.0CPE matchmatch criteria | cpe:2.3:a:blogengine:blogengine.net:3.3.8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.