{"api_version":"1","generated_at":"2026-07-24T00:33:43+00:00","cve":"CVE-2018-1000811","urls":{"html":"https://cve.report/CVE-2018-1000811","api":"https://cve.report/api/cve/CVE-2018-1000811.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-1000811","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000811"},"summary":{"title":"CVE-2018-1000811","description":"bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP code.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-12-20 15:29:00","updated_at":"2019-01-07 19:04:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/46060/","name":"46060","refsource":"EXPLOIT-DB","tags":["Third Party Advisory","VDB Entry"],"title":"bludit Pages Editor 3.0.0 - Arbitrary File Upload - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/bludit/bludit/issues/812","name":"https://github.com/bludit/bludit/issues/812","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Arbitrary File Upload - Security · Issue #812 · bludit/bludit · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-1000811","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000811","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"1000811","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bludit","cpe5":"bludit","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1000811","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bludit","cpe5":"bludit","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","DATE_ASSIGNED":"2018-11-27T13:54:33.452834","DATE_REQUESTED":"2018-10-04T17:36:25","ID":"CVE-2018-1000811","REQUESTER":"bousalman@protonmail.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"46060","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/46060/"},{"name":"https://github.com/bludit/bludit/issues/812","refsource":"MISC","url":"https://github.com/bludit/bludit/issues/812"}]}},"nvd":{"publishedDate":"2018-12-20 15:29:00","lastModifiedDate":"2019-01-07 19:04:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bludit:bludit:3.0.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"1000811","Ordinal":"140600","Title":"CVE-2018-1000811","CVE":"CVE-2018-1000811","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"1000811","Ordinal":"1","NoteData":"bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP code.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"1000811","Ordinal":"2","NoteData":"2018-12-20","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"1000811","Ordinal":"3","NoteData":"2018-12-27","Type":"Other","Title":"Modified"}]}}}