Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-25297
HistoryFeb 17, 2024 - 12:00 a.m.

CVE-2024-25297

2024-02-1700:00:00
mitre
github.com
1
bludit cms
cross site scripting
remote attackers
arbitrary code
sensitive information
edit-content.php
cve-2024-25297

AI Score

6.3

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:bludit:bludit:3.15:*:*:*:*:*:*:*"
    ],
    "vendor": "bludit",
    "product": "bludit",
    "versions": [
      {
        "status": "affected",
        "version": "3.15"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.3

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-25297