vendor:
Bolt CMS
by:
Raif Berkay Dincel
6.1
CVSS
MEDIUM
Cross-Site Scripting
Unknown
CWE
Product Name: Bolt CMS
Affected Version From: Unknown
Affected Version To: 3.6.2002
Patch Exists: NO
Related CWE: CVE-2018-19933
CPE: Unknown
Platforms Tested: Parrot Security OS, Linux Mint, Windows 10
2018
Bolt CMS <3.6.2 - Cross-Site Scripting
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
Mitigation:
Unknown