High severity8.5NVD Advisory· Published Feb 8, 2022· Updated Jun 17, 2026
CVE-2022-23626
CVE-2022-23626
Description
m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions imagecreatefrom* and image* have not been checked properly. Although PHP issued warnings and the upload function returned false, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/m1k1o/blog/commit/6f5e59f1401c4a3cf2e518aa85b231ea14e8a2efnvdPatchThird Party Advisory
- packetstormsecurity.com/files/167235/m1k1os-Blog-1.3-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- github.com/m1k1o/blog/security/advisories/GHSA-wmqj-5v54-24x4nvdThird Party Advisory
News mentions
0No linked articles in our index yet.