Impact
A stored cross‑site scripting flaw in Bludit 4.0.0‑beta permits an authenticated user with the Author role to upload a specially crafted SVG file as the site logo, embedding a <script> tag. When the logo is viewed by any visitor, the embedded script runs in the victim’s browser, enabling arbitrary client‑side code execution. This vulnerability allows attackers to deface the site, steal session cookies, or perform other client‑side attacks. The weakness is classified as CWE‑79.
Affected Systems
Bludit Bludit 4.0.0‑beta is affected. No other product or version information is provided.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity; EPSS is not available and the vulnerability is not listed in CISA KEV. The attack requires the user to be authenticated as an Author, which is a relatively low privilege but still attainable by many site contributors. Because the flaw is a stored XSS, its impact depends on the number and type of visitors who view the logo, but any such user is exposed. Exploitation is straightforward once the user supplies an SVG upload; no additional network or privilege escalation steps are needed.
OpenCVE Enrichment