CVE-2021-25808: Code Injection
Published Jul 23, 2021
·Updated
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
Affected Software
1 affected component
Bludit bludit=3.13.1
Event History
Jul 23, 2021
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this code injection vulnerability?
The vulnerability ID for this code injection vulnerability is CVE-2021-25808.
2
What is the affected software version for this vulnerability?
The affected software version for this vulnerability is Bludit 3.13.1.
3
What is the severity of CVE-2021-25808?
The severity of CVE-2021-25808 is 7.8 (high).
4
How can attackers exploit CVE-2021-25808?
Attackers can exploit CVE-2021-25808 by executing arbitrary code via a crafted ZIP file in backup/plugin.php of Bludit 3.13.1.
5
Is there a fix available for CVE-2021-25808?
Yes, a fix is available for CVE-2021-25808. It is recommended to update to a patched version of Bludit to mitigate the vulnerability.