Bludit是一套开源的轻量级博客内容管理系统(CMS)。 Bludit存在安全漏洞,该漏洞源于使用可预测的方法与MD5哈希算法相结合来生成敏感令牌,允许攻击者针对Bludit API进行身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-24553 | Bludit uses SHA1 as Password Hashing Algorithm | |
| CVE-2024-24552 | Bludit is Vulnerable to Session Fixation | |
| CVE-2024-24551 | Bludit - Remote Code Execution (RCE) through Image API | |
| CVE-2024-24550 | Bludit - Remote Code Execution (RCE) through File API |
No comments yet