CVE-2023-24674
- EPSS 0.02%
- Veröffentlicht 01.09.2023 10:15:07
- Zuletzt bearbeitet 21.11.2024 07:48:17
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.
CVE-2020-20210
- EPSS 0.81%
- Veröffentlicht 26.06.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:11:54
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
CVE-2023-34845
- EPSS 0.5%
- Veröffentlicht 16.06.2023 04:15:14
- Zuletzt bearbeitet 21.11.2024 08:07:37
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's se...
CVE-2023-31698
- EPSS 0.45%
- Veröffentlicht 17.05.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:02:09
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through...
CVE-2023-31572
- EPSS 0.14%
- Veröffentlicht 16.05.2023 14:15:09
- Zuletzt bearbeitet 23.01.2025 15:15:08
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.
- EPSS 0.61%
- Veröffentlicht 11.05.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:02
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
CVE-2022-1590
- EPSS 0.26%
- Veröffentlicht 05.05.2022 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:01
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> l...
CVE-2021-45744
- EPSS 3%
- Veröffentlicht 06.01.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:00
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
CVE-2021-45745
- EPSS 2.68%
- Veröffentlicht 06.01.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:00
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.
CVE-2021-35323
- EPSS 3.03%
- Veröffentlicht 19.10.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:13
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.