Medium severity6.5NVD Advisory· Published May 18, 2022· Updated Jun 17, 2026
CVE-2022-28921
CVE-2022-28921
Description
A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- BlogEngine.Net/BlogEngine.Netdescription
- Range: = 3.3.8.0
- cpe:2.3:a:blogengine:blogengine.net:3.3.8.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.0xlanks.me/blog/cve-2022-28921-advisory/nvdExploitThird Party Advisory
- blogengine.ionvdProduct
News mentions
0No linked articles in our index yet.