Diego Najar

2 exploits Active since Jun 2019
CVE-2019-12548 WRITEUP HIGH WRITEUP
Bludit < 3.9.0 - Unrestricted File Upload
Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload-logo.
CVSS 8.8
CVE-2019-12742 WRITEUP HIGH WRITEUP
Bludit < 3.9.1 - IDOR
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/controllers/user-password.php Insecure Direct Object Reference (a modified username POST parameter).
CVSS 8.8