Vulnerabilities > CVE-2020-8811 - Missing Authorization vulnerability in Bludit 3.10.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
bludit
CWE-862

Summary

ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.

Vulnerable Configurations

Part Description Count
Application
Bludit
1

Common Weakness Enumeration (CWE)