Vulnerability Description
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bludit | Bludit | 3.12.0 |
Related Weaknesses (CWE)
References
- https://github.com/bludit/bludit/issues/1218ExploitIssue TrackingThird Party Advisory
- https://github.com/bludit/bludit/issues/1218ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-23765?
CVE-2020-23765 is a vulnerability with a CVSS score of 7.2 (HIGH). A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe ...
How severe is CVE-2020-23765?
CVE-2020-23765 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23765?
Check the references section above for vendor advisories and patch information. Affected products include: Bludit Bludit.