PT-2021-10502 · Bludit · Bludit

Zongdeiqianxing

·

Published

2021-08-31

·

Updated

2021-09-08

·

CVE-2020-20495

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: bludit version 3.13.0
Description: The issue concerns an arbitrary file deletion vulnerability in the backup plugin. This vulnerability can be exploited via the deleteBackup parameter.
Recommendations: For bludit version 3.13.0, consider disabling the backup plugin or restricting access to the deleteBackup parameter until a fix is available. Avoid using the deleteBackup parameter in the affected backup plugin to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-20495

Affected Products

Bludit