SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-4040

Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint.

MEDIUM 4.3EPSS 1.77%

Does this matter?

Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.

Description

Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
1.77% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
boltcms/bolt
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.