Bludit CMS 3.22.0 及之前版本存在一个缺失授权检查的安全漏洞。该漏洞允许拥有“作者(Author)”或“编辑(Editor)”角色的已认证用户,通过利用 bl-kernel/ajax/content-get-list.php 文件中的 content-get-list AJAX 端点,读取任何其他用户(包括管理员)的私有草稿和计划发布文章的完整内容。 攻击者可以向管理员 AJAX 端点发送一个已认证的 GET 请求,并将 draft 参数设置为 true,从而绕过所有权限制触发 getList()
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bludit | Bludit CMS | ≤ 3.22.0 |
affected |
≤ 4.0.0-beta-1 |
affected | ||
≤ 074773eff34b91c002ab9d99029a3edca4934bf1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bludit | Bludit CMS | 0 ~ 3.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93366 | 5.4 MEDIUM | Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endpoints |
| CVE-2026-93364 | 4.3 MEDIUM | Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit() |
No comments yet