Bludit version 3.9.2 suffers from a directory traversal vulnerability.
04b5f1aa55ee5015b2d0e84c14444296ff3198d5f968e38841b92889937bd179
Bludit version 3.9.12 suffers from a directory traversal vulnerability.
ddd1cd731a420cbe6faa2fe44005c2c0f117be450077aca8113fcc5f830dc1b2
This Metasploit module exploits a vulnerability in Bludit. A remote user could abuse the uuid parameter in the image upload feature in order to save a malicious payload anywhere onto the server, and then use a custom .htaccess file to bypass the file extension check to finally get remote code execution.
446227cfe4396e17a646d44fe472ff2d78be469000650a8277e08728e69d08a8