Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown
CVE-2020-20210
Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
0
Attacker Value
Unknown
CVE-2023-34845
Disclosure Date: June 16, 2023 (last updated December 31, 2023)
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
0
Attacker Value
Unknown
CVE-2023-31698
Disclosure Date: May 17, 2023 (last updated December 31, 2023)
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
0
Attacker Value
Unknown
CVE-2023-31572
Disclosure Date: May 16, 2023 (last updated October 08, 2023)
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.
0
Attacker Value
Unknown
CVE-2020-19228
Disclosure Date: May 11, 2022 (last updated October 07, 2023)
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
0
Attacker Value
Unknown
CVE-2022-1590
Disclosure Date: May 05, 2022 (last updated October 07, 2023)
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2021-45745
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.
0
Attacker Value
Unknown
CVE-2021-45744
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
0
Attacker Value
Unknown
CVE-2021-35323
Disclosure Date: October 19, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
0
Attacker Value
Unknown
CVE-2020-20495
Disclosure Date: September 01, 2021 (last updated November 29, 2024)
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
0