Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown

CVE-2020-20210

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
Attacker Value
Unknown

CVE-2023-34845

Disclosure Date: June 16, 2023 (last updated December 31, 2023)
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
Attacker Value
Unknown

CVE-2023-31698

Disclosure Date: May 17, 2023 (last updated December 31, 2023)
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
Attacker Value
Unknown

CVE-2023-31572

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.
Attacker Value
Unknown

CVE-2020-19228

Disclosure Date: May 11, 2022 (last updated October 07, 2023)
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2022-1590

Disclosure Date: May 05, 2022 (last updated October 07, 2023)
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2021-45745

Disclosure Date: January 06, 2022 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.
Attacker Value
Unknown

CVE-2021-45744

Disclosure Date: January 06, 2022 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
Attacker Value
Unknown

CVE-2021-35323

Disclosure Date: October 19, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
Attacker Value
Unknown

CVE-2020-20495

Disclosure Date: September 01, 2021 (last updated November 29, 2024)
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.