PT-2020-14127 · Bludit · Bludit

Nullb8

·

Published

2020-06-24

·

Updated

2020-06-30

·

CVE-2020-15026

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bludit version 3.12.0
Description The issue allows admins to use a directory traversal approach for arbitrary file download via the "backup/plugin.php" file. This can be achieved by exploiting the "/plugin-backup-download?file=../" endpoint.
Recommendations For Bludit version 3.12.0, consider restricting access to the backup/plugin.php file and the /plugin-backup-download endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the file parameter in the /plugin-backup-download endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15026

Affected Products

Bludit