CVE-2023-53907
MEDIUMBludit <3.13.1 - Authenticated File Download
Title source: llmDescription
Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.0039
EPSS Percentile
59.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
Bludit/Backup Plugin
3.13.1
bludit/bludit
< 3.13.1
Published
Dec 17, 2025
Tracked Since
Feb 18, 2026