CVE-2020-8812: XSS
Published Feb 7, 2020
·Updated
DISPUTED Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug."
Affected Software
1 affected component
Bludit bludit=3.10.0
Event History
Feb 7, 2020
CVE Published
via MITRE·10:59 PM
Data Sourced
via MITRE·10:59 PM
Description
Disputed
11:15 PM
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-8812?
CVE-2020-8812 is a vulnerability in Bludit 3.10.0 that allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor.
2
How severe is CVE-2020-8812?
CVE-2020-8812 has a severity rating of 5.4, which is considered medium.
3
What software versions are affected by CVE-2020-8812?
CVE-2020-8812 affects Bludit version 3.10.0.
4
How can Editor or Author roles insert malicious JavaScript on the WYSIWYG editor in Bludit 3.10.0?
Editor or Author roles can insert malicious JavaScript on the WYSIWYG editor in Bludit 3.10.0, allowing them to potentially execute harmful actions.
5
Is CVE-2020-8812 considered a bug by the vendor?
The vendor disputes that CVE-2020-8812 is a bug.