CVE-2018-1000811

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
20/12/2018
Last modified:
07/01/2019

Description

bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bludit:bludit:3.0.0:*:*:*:*:*:*:*