PT-2021-10248 · Bludit · Bludit

Liao10086

·

Published

2021-08-20

·

Updated

2021-08-24

·

CVE-2020-18879

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Bludit version 3.8.1
Description: The issue allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'. This is an instance of an unrestricted file upload, which can be exploited to gain unauthorized access and control.
Recommendations: For Bludit version 3.8.1, consider disabling the 'bl-kereln/ajax/upload-logo.php' component until a patch is available to prevent the upload of malicious files. Restrict access to this component to minimize the risk of exploitation. Avoid using this component for file uploads until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18879

Affected Products

Bludit