vendor:
Bludit
by:
James Green
8.8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Bludit
Affected Version From: 3.9.2
Affected Version To: 3.9.2
Patch Exists: YES
Related CWE: CVE-2019-16113
CPE: a:bludit:bludit:3.9.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux Ubuntu 19.10 Eoan
2020
Bludit 3.9.2 – Directory Traversal
Bludit 3.9.2 is vulnerable to a directory traversal vulnerability. An attacker can exploit this vulnerability to upload arbitrary files to the web server, which can lead to remote code execution. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'dir' parameter of the 'upload-images' AJAX request. An attacker can exploit this vulnerability by sending a specially crafted AJAX request with a malicious file to the vulnerable application. Successful exploitation of this vulnerability can result in remote code execution.
Mitigation:
Upgrade to the latest version of Bludit 3.9.2 or later.