ZeroHour

CVE-2019-10874

PoC ×3
CVSS 3.0
8.8 high
EPSS
5%p91
Published
()
Modified
Description

Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.

Vendors
boltcms
Products
bolt
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.