CVE-2017-17793: Blogotext Project Blogotext
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the archiv~1.zip name (aka an 8.3 filename).
Affected products
- Blogotext Project Blogotext: up to and including 3.7.6
Published 2017-12-20. Last modified 2026-06-17.