PT-2026-98954 · Unknown · Bludit Cms
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bludit CMS versions prior to 3.22.1
Description
An authorization bypass allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators. This occurs by supplying arbitrary
uuid parameters to unprotected AJAX endpoints. Attackers can retrieve page UUIDs for all users via the 'content-get-list' endpoint and then submit crafted POST requests to the 'list-images' and 'delete-image' endpoints in 'bl-kernel/ajax/' to access and destroy media files outside their own pages, bypassing the IMAGE RESTRICT isolation control.Recommendations
Update Bludit CMS to version 3.22.1 or later.
Restrict access to the 'bl-kernel/ajax/' endpoints to minimize the risk of exploitation.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bludit Cms