Executive brief
Bludit, a flat-file content management system, is vulnerable to an attack that could allow unauthorized changes to a website's configuration. By tricking a logged-in administrator into clicking a malicious link, an attacker can force the website to uninstall plugins or install new themes without the administrator's consent. This could lead to a loss of website functionality or the introduction of malicious code through unauthorized themes.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Bludit version 3.16.1 within the '/admin/uninstall-plugin/' and '/admin/install-theme/' endpoints. The application fails to implement anti-CSRF tokens or validate request origins (Referer/Origin headers) for these sensitive administrative actions. An attacker can exploit this by hosting a malicious HTML page that uses JavaScript to silently submit requests to a victim's Bludit instance. If an authenticated administrator visits the malicious page, the attacker can force the uninstallation of plugins or the installation of arbitrary themes. This could result in a denial of service for specific site features or remote code execution if a malicious theme is installed. As of the advisory date, the issue was reported in GitHub issue #1577 and remains unpatched in version 3.16.1.
Affected products
- Bludit Bludit <= 3.16.1
Timeline
- 2024-08-21: disclosed: Vulnerability reported on GitHub issues
- 2026-02-23: advisory: NVD and VulnCheck published advisory