Описание
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-31698
- https://github.com/bludit/bludit/issues/1212#issuecomment-649514491
- https://github.com/bludit/bludit/issues/1369#issuecomment-940806199
- https://github.com/bludit/bludit/issues/1509
- http://packetstormsecurity.com/files/172462/Bludit-CMS-3.14.1-Cross-Site-Scripting.html
Связанные уязвимости
CVSS3: 5.4
nvd
больше 2 лет назад
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).