{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bludit-cms-3.22.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bludit CMS (3.22.0)"],"_cs_severities":["medium"],"_cs_tags":["webapps","xss","injection"],"_cs_type":"advisory","_cs_vendors":["Bludit"],"content_html":"\u003cp\u003eBludit CMS version 3.22.0 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability due to incomplete sanitization of SVG files. The application's \u003ccode\u003esanitizeSVG()\u003c/code\u003e function fails to remove XML processing instructions, specifically the \u003ccode\u003e\u0026lt;?xml-stylesheet?\u0026gt;\u003c/code\u003e directive. An attacker can craft a malicious SVG file containing an XSLT transformation that points to a local or remote stylesheet. When this file is uploaded through the administrative interface and subsequently viewed by a user, the XSLT processor executes the embedded JavaScript. This allows an attacker to achieve unauthorized script execution in the context of the user's browser, which can lead to session hijacking, administrative credential theft, or further actions performed on behalf of the victim.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates as an administrative user or gains access to the image upload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious SVG file containing an \u003ccode\u003e\u0026lt;?xml-stylesheet?\u0026gt;\u003c/code\u003e XML processing instruction.\u003c/li\u003e\n\u003cli\u003eAttacker embeds an XSLT transformation within the SVG that includes a \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e block containing the desired JavaScript payload.\u003c/li\u003e\n\u003cli\u003eAttacker sends a \u003ccode\u003ePOST\u003c/code\u003e request to \u003ccode\u003e/admin/ajax/upload-images\u003c/code\u003e with the malicious SVG file as a multipart/form-data payload.\u003c/li\u003e\n\u003cli\u003eThe application fails to strip the XML processing instructions in \u003ccode\u003esanitizeSVG()\u003c/code\u003e and stores the file in \u003ccode\u003e/bl-content/uploads/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker or a victim navigates to the URL of the uploaded SVG file.\u003c/li\u003e\n\u003cli\u003eThe browser renders the SVG, triggers the XSLT stylesheet, and executes the embedded JavaScript payload.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in the victim's browser session. If an administrator is tricked into viewing the malicious file, the attacker can perform unauthorized administrative actions, modify site content, or steal session cookies, potentially leading to full site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVerify your Bludit CMS version and upgrade to a patched release if available.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side content-type validation and disable the execution of XML processing instructions for user-uploaded SVG files.\u003c/li\u003e\n\u003cli\u003eUse Content Security Policy (CSP) headers to restrict script execution for content hosted on the site's media storage domain.\u003c/li\u003e\n\u003cli\u003eDeploy the suggested web server detection rule to monitor for suspicious file uploads containing XML stylesheet references.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T14:31:44Z","date_published":"2026-09-01T14:31:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bludit-xss/","summary":"Bludit CMS version 3.22.0 contains a stored XSS vulnerability in its SVG upload process, allowing attackers to execute arbitrary JavaScript via malicious XML processing instructions.","title":"Stored XSS Vulnerability in Bludit CMS","url":"https://feed.craftedsignal.io/briefs/2026-09-bludit-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Bludit CMS (3.22.0)","version":"https://jsonfeed.org/version/1.1"}