PT-2020-20298 · Bludit · Bludit

·

CVE-2020-8812

·

Published

2020-02-07

·

Updated

2024-08-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bludit version 3.10.0
Description The issue allows users with Editor or Author roles to insert malicious JavaScript into the WYSIWYG editor. It's noted that the vendor considers this behavior as "not a bug".
Recommendations For Bludit version 3.10.0, consider restricting access to the WYSIWYG editor for users with Editor or Author roles until a resolution is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8812

Affected Products

Bludit