PT-2022-13987 · Bludit · Bludit

Joinia

·

Published

2022-05-05

·

Updated

2022-05-13

·

CVE-2022-1590

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bludit version 3.13.1
Description A vulnerability was found in the New Content module, specifically affecting the endpoint "/admin/new-content". The issue arises from the manipulation of the content argument with malicious input, such as <script>alert(1)</script>, leading to cross-site scripting. This attack can be initiated remotely but requires authentication. The exploit has been publicly disclosed.
Recommendations For Bludit version 3.13.1, consider disabling access to the "/admin/new-content" endpoint until a patch is available. Additionally, restrict the use of the content argument in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1590

Affected Products

Bludit