Bludit
cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*
- < 3.13.1
This vulnerability is being actively exploited in the wild.
A vulnerability exists in Bludit versions prior to 3.13.1 within the Backup Plugin, allowing authenticated users to download arbitrary files. This issue arises from improper validation of file path parameters, enabling directory traversal attacks to access sensitive system files.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.
To reproduce this vulnerability, log into a Bludit site running a version prior to 3.13.1. Once logged in, navigate to the Backup Plugin's download feature. By manipulating the file path parameters to include directory traversal sequences, it is possible to access and download arbitrary files from the server, including sensitive system files.
Users are advised to update Bludit to version 3.13.1 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.