CVE-2020-20210: Malicious File Upload
Published Jun 26, 2023
·Updated
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
Affected Software
1 affected component
Bludit bludit=3.9.2
Event History
Jun 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2020-20210?
CVE-2020-20210 is a vulnerability in Bludit 3.9.2 that allows remote code execution (RCE) via the /admin/ajax/upload-images endpoint.
2
How severe is CVE-2020-20210?
CVE-2020-20210 has a severity rating of 8.8, which is considered high.
3
How can I fix CVE-2020-20210?
To fix CVE-2020-20210, you should update Bludit to version 3.9.3 or later, as this vulnerability has been fixed in newer versions.
4
Where can I find more information about CVE-2020-20210?
You can find more information about CVE-2020-20210 on the GitHub page for the Bludit project: [link](https://github.com/bludit/bludit/issues/1079).
5
What is CWE-434?
CWE-434 is a CWE classification for vulnerabilities related to unrestricted upload of file with dangerous type.