CVE-2019-16113

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
08/09/2019
Last modified:
26/04/2022

Description

Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bludit:bludit:3.9.2:*:*:*:*:*:*:*