CVE-2020-20210
- EPSS 1.04%
- Veröffentlicht 26.06.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:11:54
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
CVE-2023-34845
- EPSS 0.8%
- Veröffentlicht 16.06.2023 04:15:14
- Zuletzt bearbeitet 21.11.2024 08:07:37
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's se...
CVE-2023-31698
- EPSS 2.59%
- Veröffentlicht 17.05.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:02:09
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through...
CVE-2023-31572
- EPSS 0.84%
- Veröffentlicht 16.05.2023 14:15:09
- Zuletzt bearbeitet 23.01.2025 15:15:08
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.
- EPSS 1.2%
- Veröffentlicht 11.05.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:02
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
CVE-2022-1590
- EPSS 0.63%
- Veröffentlicht 05.05.2022 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:01
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> l...
CVE-2021-45745
- EPSS 1.44%
- Veröffentlicht 06.01.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:00
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.
CVE-2021-45744
- EPSS 1.44%
- Veröffentlicht 06.01.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:00
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
CVE-2021-35323
- EPSS 5.62%
- Veröffentlicht 19.10.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:13
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
CVE-2020-20495
- EPSS 1.51%
- Veröffentlicht 01.09.2021 00:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:07
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.