CVE-2020-15006: XSS
Published Jun 24, 2020
·Updated
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
Affected Software
1 affected component
Bludit bludit=3.12.0
Event History
Jun 24, 2020
CVE Published
via MITRE·10:41 AM
Data Sourced
via MITRE·10:41 AM
Description
Frequently Asked Questions
1
What is CVE-2020-15006?
CVE-2020-15006 is a vulnerability in Bludit 3.12.0 that allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
2
How severe is CVE-2020-15006?
CVE-2020-15006 is classified as a medium severity vulnerability with a CVSS score of 5.4.
3
Is Bludit version 3.12.0 affected by CVE-2020-15006?
Yes, Bludit version 3.12.0 is affected by CVE-2020-15006.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-15006?
The Common Weakness Enumeration (CWE) ID for CVE-2020-15006 is CWE-79.
5
How can I fix CVE-2020-15006?
To fix CVE-2020-15006, it is recommended to update to a version of Bludit that has addressed the vulnerability.