VYPR
Critical severity9.8GHSA Advisory· Published Apr 16, 2019· Updated Jun 17, 2026

CVE-2019-9845

CVE-2019-9845

Description

madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
MadsKristensen.AspNetCore.MiniblogNuGet
<= 1.0.3

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.