Intel

AIKIDO-2024-10165

putyourlightson/craft-blitz is vulnerable to Malicious Code

Malicious Code Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 3, 2024

90

Critical Risk

This Affects:

phpputyourlightson/craft-blitz
3.11.1 - 3.14.0
Fixed in 3.15.0
4.0.0 - 4.11.2
Fixed in 4.12.0
Are you affected? Scan for Free

TL;DR

putyourlightson/craft-blitz uses polyfill[.]io for IE support, this library was taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

putyourlightson/craft-blitz is vulnerable to Malicious Code in versions 3.11.1 - 3.14.0 and 4.0.0 - 4.11.2.

How to fix this

Upgrade the putyourlightson/craft-blitz library to the patch version.