CVE-2023-34845: Bludit
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
Affected products
- Bludit Bludit: version 3.14.1 only
Published 2023-06-16. Last modified 2026-06-17.