Bludit · Bludit · CVE-2021-35323
Name of the Vulnerable Software and Affected Versions:
bludit version 3-13-1
Description:
A Cross Site Scripting (XSS) issue exists via the `username` in the "admin/login" API endpoint.
Recommendations:
For version 3-13-1, avoid using the `username` variable in the "admin/login" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the admin/login endpoint to minimize the risk of exploitation.