First published: Mon Jun 03 2019(Updated: )
Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload-logo.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bludit | <3.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12548 is a vulnerability in Bludit before version 3.9.0 that allows remote code execution for an authenticated user by uploading a PHP file while changing the logo through /admin/ajax/upload-logo.
Yes, Bludit is affected by CVE-2019-12548.
CVE-2019-12548 has a severity rating of 8.8 (High).
To fix CVE-2019-12548, you should upgrade to Bludit version 3.9.0 or later.
You can find more information about CVE-2019-12548 on the following websites: - [GitHub Commit](https://github.com/bludit/bludit/commit/d0843a4070c7d7fa596a7eb2130be15383013487) - [GitHub Comparison](https://github.com/bludit/bludit/compare/5e5957c...77e85e7) - [Bludit Releases](https://github.com/bludit/bludit/releases/tag/3.9.0)