First published: Thu May 05 2022(Updated: )
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bludit | =3.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1590 is a vulnerability found in Bludit 3.13.1 that leads to cross-site scripting (XSS) through the /admin/new-content endpoint of the New Content module.
CVE-2022-1590 has a severity rating of medium, with a CVSS score of 5.4.
CVE-2022-1590 affects Bludit version 3.13.1.
The CWE ID for CVE-2022-1590 is CWE-79, which is for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To mitigate the CVE-2022-1590 vulnerability in Bludit 3.13.1, it is recommended to update to a secure version that includes a fix for the vulnerability.