Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload
Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the site logo. A stored script tag in the SVG executes in the browser of any user who loads the logo.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Bludit 跨站脚本漏洞
Vulnerability Description
Bludit是Bludit公司开源的一个内容管理系统。 Bludit 4.0.0-beta版本存在跨站脚本漏洞,该漏洞源于上传特制SVG文件作为站点logo时,/admin/ajax/logo-upload端点未调用sanitizeSVG或transformImage直接移动文件至web根目录,可能导致低权限认证用户注入任意JavaScript,存储的脚本在加载logo的用户浏览器中执行。
CVSS Information
N/A
Vulnerability Type
N/A