VulnerabilityModified
CVE-2020-4040
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint.
MEDIUM 4.3EPSS 1.77%
Does this matter?
Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.
Description
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- boltcms/bolt
- Source
- security-advisories@github.com
References
- http://packetstormsecurity.com/files/158299/Bolt-CMS-3.7.0-XSS-CSRF-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jul/4Exploit, Mailing List, Third Party Advisory
- https://github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419fPatch, Third Party Advisory
- https://github.com/bolt/bolt/pull/7853Patch, Third Party Advisory
- https://github.com/bolt/bolt/security/advisories/GHSA-2q66-6cc3-6xm8Patch, Third Party Advisory
- http://packetstormsecurity.com/files/158299/Bolt-CMS-3.7.0-XSS-CSRF-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jul/4Exploit, Mailing List, Third Party Advisory
- https://github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419fPatch, Third Party Advisory
- https://github.com/bolt/bolt/pull/7853Patch, Third Party Advisory
- https://github.com/bolt/bolt/security/advisories/GHSA-2q66-6cc3-6xm8Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.