Bludit CMS 3.22.0 及之前版本存在一个授权绕过漏洞,允许具有“作者”(Author)角色的已认证用户通过向未受保护的 AJAX 端点提供任意的 UUID 参数,枚举并删除属于其他用户(包括管理员)所拥有页面的媒体文件。攻击者可以通过 content-get-list 端点获取所有用户的页面 UUID,然后向 bl-kernel/ajax/ 下的 list-images 和 delete-image 端点提交构造的 POST 请求,从而访问并销毁其自有页面之外的媒体文件,从而绕过 IMAGE_REST
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bludit | Bludit CMS | ≤ 3.22.0 |
affected |
≤ 4.0.0-beta-1 |
affected | ||
≤ 074773eff34b91c002ab9d99029a3edca4934bf1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bludit | Bludit CMS | 0 ~ 3.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93365 | 6.5 MEDIUM | Bludit CMS 3.22.0 Missing Authorization via content-get-list AJAX Endpoint |
| CVE-2026-93364 | 4.3 MEDIUM | Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit() |
No comments yet