Summary
Detail | |||
---|---|---|---|
Vendor | Bolt | First view | 2017-07-17 |
Product | Bolt Cms | Last view | 2022-09-16 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:bolt:bolt_cms:3.2.14:*:*:*:*:*:*:* | 5 |
cpe:2.3:a:bolt:bolt_cms:*:*:*:*:*:*:*:* | 3 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.8 | 2022-09-16 | CVE-2022-36532 | Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution. |
8.8 | 2022-04-11 | CVE-2021-40219 | Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution. |
6.1 | 2018-12-17 | CVE-2018-19933 | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. |
5.4 | 2017-07-17 | CVE-2017-11128 | Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry. |
5.4 | 2017-07-17 | CVE-2017-11127 | Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
75% (3) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
25% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |