Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.
References
Link | Resource |
---|---|
https://github.com/bludit/bludit/issues/1132 | Exploit Issue Tracking Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-07T22:59:35
Updated: 2020-02-07T22:59:35
Reserved: 2020-02-07T00:00:00
Link: CVE-2020-8812
JSON object: View
NVD Information
Status : Modified
Published: 2020-02-07T23:15:10.933
Modified: 2024-05-17T01:51:13.000
Link: CVE-2020-8812
JSON object: View
Redhat Information
No data.
CWE