Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2022-1590

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2021-35323

Disclosure Date: October 19, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
Attacker Value
Unknown

CVE-2021-25808

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.