Record summary

CVE-2023-53907 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 18, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.13.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBBludit < 3.13.1 Backup Plugin - Arbitrary File Download (Authenticated)ExploitDB exploitby Antonio CuomoNot analyzed1 file
ExploitDB

PoC details

References

4