CVE-2020-18879
- EPSS 3.13%
- Veröffentlicht 20.08.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:50
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
CVE-2021-25808
- EPSS 1.22%
- Veröffentlicht 23.07.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:28
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
CVE-2020-23765
- EPSS 1.1%
- Veröffentlicht 21.05.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:14:04
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the se...
CVE-2020-18190
- EPSS 1.94%
- Veröffentlicht 02.10.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:08:28
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.
CVE-2020-15026
- EPSS 1.3%
- Veröffentlicht 24.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:39
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.
CVE-2020-15006
- EPSS 0.51%
- Veröffentlicht 24.06.2020 11:15:11
- Zuletzt bearbeitet 21.11.2024 05:04:36
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
CVE-2020-13889
- EPSS 0.86%
- Veröffentlicht 06.06.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:05
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
CVE-2020-8812
- EPSS 0.61%
- Veröffentlicht 07.02.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:39:29
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.
CVE-2020-8811
- EPSS 0.55%
- Veröffentlicht 07.02.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:39:29
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.
CVE-2019-17240
- EPSS 39.6%
- Veröffentlicht 06.10.2019 19:15:09
- Zuletzt bearbeitet 21.11.2024 04:31:55
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.