CVE-2023-31698
MEDIUMBludit 3.14.1 - Stored Cross-Site Scripting via SVG Site Logo Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-31698. PoCs published by Rahad Chowdhury.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Bludit CMS v3.14.1 by uploading a malicious SVG file containing JavaScript code. The payload triggers an alert popup when the uploaded logo is viewed.
Description
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Bludit CMS v3.14.1 by uploading a malicious SVG file containing JavaScript code. The payload triggers an alert popup when the uploaded logo is viewed.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N