Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Thatsa9

#28107of 56,337
9.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-20297
4.3
2020-02-07
Bludit · Bludit · CVE-2020-8811
**Name of the Vulnerable Software and Affected Versions** Bludit version 3.10.0 **Description** The issue allows authenticated users to change other users' profile pictures due to a problem in the ajax/profile-picture-upload.php file. **Recommendations** For Bludit version 3.10.0, update to a newer version that contains a fix for this issue.
PT-2020-20298
5.4
2020-02-07
Bludit · Bludit · CVE-2020-8812
**Name of the Vulnerable Software and Affected Versions** Bludit version 3.10.0 **Description** The issue allows users with Editor or Author roles to insert malicious JavaScript into the WYSIWYG editor. It's noted that the vendor considers this behavior as "not a bug". **Recommendations** For Bludit version 3.10.0, consider restricting access to the WYSIWYG editor for users with Editor or Author roles until a resolution is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.