# BlueImp file upload vulnerability relevant to brXM CMS?

**URL:** <https://community.bloomreach.com/t/blueimp-file-upload-vulnerability-relevant-to-brxm-cms/2239>\
**Category:** Experience Manager (PaaS/OnPrem)\
**Created:** [November 17, 2020, 6:51pm UTC](https://community.bloomreach.com/t/blueimp-file-upload-vulnerability-relevant-to-brxm-cms/2239 "2020-11-17T18:51:46Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Patrick\_McInerney](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/patrick_mcinerney/32/282_2.png) [@Patrick\_McInerney](https://community.bloomreach.com/u/Patrick_McInerney)\
**Post date:** [November 17, 2020, 6:51pm UTC](https://community.bloomreach.com/t/blueimp-file-upload-vulnerability-relevant-to-brxm-cms/2239/1 "2020-11-17T18:51:46Z")

</div>

Hello,

There is a known security vulnerability in the Blueimp jQuery File Upload library for versions released prior to Oct 13, 2018 (v9.22.1).

> **[NVD - CVE-2018-9206](https://nvd.nist.gov/vuln/detail/CVE-2018-9206)**

It seems like the brXM image upload tool uses some part of this library (see screenshot), but it is difficult to tell what version and/or its exact usage so as to establish whether the vulnerability is relevant to usage of the CMS. I have made an attempt to find documentation or other info, to no avail.

Is there anyone that can confirm how Blueimp is used by brXM?

 ![Screenshot 2020-11-17 114440](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/1X/4776b150667fdede8612b6da23aa9de57183edf5.jpeg)
