Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2019-15484
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Bolt before 3.6.10 has XSS via an image's alt or title field.
0
Attacker Value
Unknown
CVE-2019-20058
Disclosure Date: June 19, 2019 (last updated November 08, 2023)
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040
0
Attacker Value
Unknown
CVE-2019-10874
Disclosure Date: April 05, 2019 (last updated November 27, 2024)
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.
0
Attacker Value
Unknown
CVE-2019-9185
Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.
0
Attacker Value
Unknown
CVE-2017-16754
Disclosure Date: November 10, 2017 (last updated November 26, 2024)
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
0
Attacker Value
Unknown
CVE-2017-11128
Disclosure Date: July 17, 2017 (last updated February 15, 2025)
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
0
Attacker Value
Unknown
CVE-2017-11127
Disclosure Date: July 17, 2017 (last updated February 15, 2025)
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
0
Attacker Value
Unknown
CVE-2015-7309
Disclosure Date: September 22, 2015 (last updated October 05, 2023)
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.
0