Remote Code Execution Vulnerability in Bludit by Bludit
CVE-2020-20210

8.8HIGH

Key Information:

Vendor

Bludit

Status
Vendor
CVE Published:
26 June 2023

What is CVE-2020-20210?

Bludit version 3.9.2 contains a security flaw that allows attackers to exploit a Remote Code Execution vulnerability via the /admin/ajax/upload-images endpoint. This vulnerability can enable unauthorized command execution, potentially giving attackers control over the affected system. It is crucial for users of Bludit to apply necessary updates and mitigations to safeguard their installations from this risk. For further details, refer to the discussion on GitHub that outlines the vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.