2019-06-03 20:38:32
mitre
PUBLISHED
Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload-logo.