vendor:
Bludit
by:
nu11secur1ty
7.5
CVSS
HIGH
Account takeover
CWE
Product Name: Bludit
Affected Version From: 4.0.0-rc-2
Affected Version To: 4.0.0-rc-2
Patch Exists:
Related CWE:
CPE:
Platforms Tested: Windows, Linux, Mac
2023
Bludit 4.0.0-rc-2 – Account takeover
The already authenticated attacker can send a normal request to change his password and then he can use the same JSON object and the vulnerable API token KEY in the same request to change the admin account password. Then he can access the admin account and he can do very malicious stuff.