CVE-2020-23765: Malicious File Upload
Published May 21, 2021
·Updated
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.
Affected Software
1 affected component
Bludit bludit=3.12.0
Event History
May 21, 2021
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-23765.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.'
3
What is the severity of CVE-2020-23765?
The severity of CVE-2020-23765 is high with a severity value of 7.2.
4
Which software version is affected by CVE-2020-23765?
Bludit version 3.12.0 is affected by CVE-2020-23765.
5
How can an attacker exploit CVE-2020-23765?
If an attacker gains Administrator rights, they can use unsafe plugins to upload a backup file and control the server.