Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3xc-px9v-223r

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

EPSS

Процентиль: 54%
0.00317
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

EPSS

Процентиль: 54%
0.00317
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22