CVE-2018-1000811

HIGH

bludit <3.0.0 - RCE

Title source: llm
STIX 2.1

Description

bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP code.

Exploits (1)

exploitdb WORKING POC
by BouSalman · textwebappsphp
https://www.exploit-db.com/exploits/46060

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46060/
Exploit, Third Party Advisory x_refsource_misc
https://github.com/bludit/bludit/issues/812

Scores

CVSS v3 8.8
EPSS 0.1186
EPSS Percentile 93.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
bludit/bludit 3.0.0
Published Dec 20, 2018
Tracked Since Feb 18, 2026