CVE-2020-4040
CSRF issue on preview pages in Bolt CMS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
Bolt CMS versión anterior a 3.7.1, carecía de protección de CSRF en el endpoint de generación de vista previa. Las vistas previas están destinadas a ser generadas por los administradores, desarrolladores, jefes de redacción y editores, que están autorizados para crear contenido en la aplicación. Pero debido a la falta de una protección de CSRF apropiada, los usuarios no autorizados podrían generar una vista previa. Esto se ha corregido en Bolt versión 3.7.1
Bolt CMS versions 3.7.0 and below suffer from cross site request forgery, cross site scripting, and remote shell upload vulnerabilities that when combined can achieve remote code execution in one click.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-30 CVE Reserved
- 2020-06-08 CVE Published
- 2020-11-15 First Exploit
- 2024-02-24 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (6)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419f | 2022-10-07 | |
https://github.com/bolt/bolt/pull/7853 | 2022-10-07 | |
https://github.com/bolt/bolt/security/advisories/GHSA-2q66-6cc3-6xm8 | 2022-10-07 |
URL | Date | SRC |
---|