CVE-2024-24551

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*

History

02 Jan 2026, 20:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Bludit
Bludit bludit
CPE cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*
References () https://www.redguard.ch/blog/2024/06/20/security-advisory-bludit/ - () https://www.redguard.ch/blog/2024/06/20/security-advisory-bludit/ - Exploit, Third Party Advisory

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://www.redguard.ch/blog/2024/06/20/security-advisory-bludit/ - () https://www.redguard.ch/blog/2024/06/20/security-advisory-bludit/ -

24 Jun 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad de seguridad en Bludit, que permite a atacantes autenticados ejecutar código arbitrario a través de Image API. Esta vulnerabilidad surge del manejo inadecuado de la carga de archivos, lo que permite a actores malintencionados cargar y ejecutar archivos PHP.

24 Jun 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-24 07:15

Updated : 2026-01-02 20:31


NVD link : CVE-2024-24551

Mitre link : CVE-2024-24551

CVE.ORG link : CVE-2024-24551


JSON object : View

Products Affected

bludit

  • bludit
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-502

Deserialization of Untrusted Data