First published: Fri Sep 01 2023(Updated: )
Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bludit | =3.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24675 is a Cross Site Scripting vulnerability in BluditCMS v.3.14.1.
CVE-2023-24675 allows attackers to execute arbitrary code via the Categories Friendly URL on BluditCMS v.3.14.1.
CVE-2023-24675 has a severity level of medium with a CVSS score of 4.8.
To fix CVE-2023-24675, update BluditCMS to a version that is not affected by the vulnerability.
Yes, you can find additional information about CVE-2023-24675 in the following references: [Link 1](https://cupc4k3.medium.com/cve-2023-24674-uncovering-a-privilege-escalation-vulnerability-in-bludit-cms-dcf86c41107) and [Link 2](https://medium.com/@cupc4k3/xss-stored-in-friendly-url-field-on-bludit-cms-641a9dd653f).