PT-2020-20298 · Bludit · Bludit

Thatsa9

·

Published

2020-02-07

·

Updated

2024-08-04

·

CVE-2020-8812

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bludit version 3.10.0
Description The issue allows users with Editor or Author roles to insert malicious JavaScript into the WYSIWYG editor. It's noted that the vendor considers this behavior as "not a bug".
Recommendations For Bludit version 3.10.0, consider restricting access to the WYSIWYG editor for users with Editor or Author roles until a resolution is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-8812

Affected Products

Bludit