PT-2022-13987 · Bludit · Bludit
Joinia
·
Published
2022-05-05
·
Updated
2022-05-13
·
CVE-2022-1590
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bludit version 3.13.1
Description
A vulnerability was found in the New Content module, specifically affecting the endpoint "/admin/new-content". The issue arises from the manipulation of the
content argument with malicious input, such as <script>alert(1)</script>, leading to cross-site scripting. This attack can be initiated remotely but requires authentication. The exploit has been publicly disclosed.Recommendations
For Bludit version 3.13.1, consider disabling access to the "/admin/new-content" endpoint until a patch is available. Additionally, restrict the use of the
content argument in this endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bludit