CVE-2019-12742: High severity bludit vulnerability
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/controllers/user-password.php Insecure Direct Object Reference (a modified username POST parameter).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-12742?
CVE-2019-12742 is a vulnerability in Bludit prior to version 3.9.1 that allows a non-privileged user to change the password of any account, including admin.
How does the vulnerability CVE-2019-12742 occur?
The vulnerability occurs due to insecure direct object reference in the 'user-password.php' file in Bludit. This can be exploited by modifying the 'username' parameter in the POST request.
What is the severity of CVE-2019-12742?
The severity of CVE-2019-12742 is rated as high with a severity value of 8.8.
Which versions of Bludit are affected by CVE-2019-12742?
Bludit versions up to, but not including, 3.9.1 are affected by CVE-2019-12742.
How can I fix CVE-2019-12742?
To fix CVE-2019-12742, users should upgrade to Bludit version 3.9.1 or later.