Bludit CMS 3.22.0 及之前版本中存在一个质量分配(mass assignment)漏洞,允许具有“作者”(Author)角色的已认证用户通过在内容保存请求中注入受限参数,来修改原本仅限管理员使用的特权页面字段。攻击者可以通过 中的 函数提交受限字段(例如 和 ),该函数在遍历 中声明的所有字段时未进行逐字段授权检查,从而导致“作者”角色能够将页面转换为静态的全站导航条目,或将页面所有权转移至任意账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bludit | Bludit CMS | ≤ 3.22.0 |
affected |
≤ 4.0.0-beta-1 |
affected | ||
≤ 074773eff34b91c002ab9d99029a3edca4934bf1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bludit | Bludit CMS | 0 ~ 3.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93365 | 6.5 MEDIUM | Bludit CMS 3.22.0 Missing Authorization via content-get-list AJAX Endpoint |
| CVE-2026-93366 | 5.4 MEDIUM | Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints |
No comments yet