Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2020-4040

Disclosure Date: June 08, 2020 (last updated February 21, 2025)
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
Attacker Value
Unknown

CVE-2019-9553

Disclosure Date: December 31, 2019 (last updated November 27, 2024)
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
Attacker Value
Unknown

CVE-2019-15485

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
0
Attacker Value
Unknown

CVE-2019-15483

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
0
Attacker Value
Unknown

CVE-2019-15484

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Bolt before 3.6.10 has XSS via an image's alt or title field.
0
Attacker Value
Unknown

CVE-2019-20058

Disclosure Date: June 19, 2019 (last updated November 08, 2023)
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040
Attacker Value
Unknown

CVE-2019-10874

Disclosure Date: April 05, 2019 (last updated November 27, 2024)
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.
0
Attacker Value
Unknown

CVE-2019-9185

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.
0
Attacker Value
Unknown

CVE-2018-19904

Disclosure Date: December 31, 2018 (last updated November 27, 2024)
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.
0
Attacker Value
Unknown

CVE-2018-19903

Disclosure Date: December 31, 2018 (last updated November 27, 2024)
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page title field.
0