PT-2017-14502 · Bludit · Bludit
Benjamin Kunz Mejri
·
Published
2017-11-06
·
Updated
2017-11-29
·
CVE-2017-16636
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bludit versions 1.5.2 through 2.0.1
Description
The issue allows remote attackers to bypass basic editor validation and trigger cross-site scripting. This is achieved by injecting code using an editor tag not recognized by the basic validation, enabling a restricted user account to inject malicious script code and perform a persistent attack against higher privilege web-application user accounts. The attack is initiated via a GET request and completed with a follow-up POST method request to save the editor context.
Recommendations
For versions 1.5.2 and 2.0.1, consider disabling the editor functionality until a patch is available to prevent the injection of malicious script code. Restrict access to the new page, new category, and edit post functions to minimize the risk of exploitation. Avoid using the editor to inject any code until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bludit