CVE-2020-18879: Malicious File Upload
Published Aug 20, 2021
·Updated
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
Affected Software
1 affected component
Bludit bludit=3.8.1
Event History
Aug 20, 2021
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-18879.
2
What is the severity level of CVE-2020-18879?
The severity level of CVE-2020-18879 is critical with a severity score of 9.8.
3
How does CVE-2020-18879 allow remote attackers to execute arbitrary code?
CVE-2020-18879 allows remote attackers to execute arbitrary code by uploading malicious files via the 'bl-kereln/ajax/upload-logo.php' component in Bludit v3.8.1.
4
What software versions are affected by CVE-2020-18879?
Bludit v3.8.1 is affected by CVE-2020-18879.
5
Is there a fix available for CVE-2020-18879?
Yes, upgrading to a version of Bludit that is not affected by CVE-2020-18879 would fix the vulnerability.