A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.
History

Fri, 02 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published: 2024-06-24T07:05:50.655Z

Updated: 2024-08-01T23:19:52.559Z

Reserved: 2024-01-25T14:02:00.526Z

Link: CVE-2024-24550

cve-icon Vulnrichment

Updated: 2024-06-24T13:33:32.615Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-24T07:15:13.580

Modified: 2026-01-02T20:19:43.760

Link: CVE-2024-24550

cve-icon Redhat

No data.