vendor:
Bolt CMS
by:
Ismail Tasdelen
6.1
CVSS
MEDIUM
Cross-site Scripting
79
CWE
Product Name: Bolt CMS
Affected Version From: 3.6.4
Affected Version To: 3.6.4
Patch Exists: Yes
Related CWE: CVE-2019-9553
CPE: a:bolt_cms:bolt_cms:3.6.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Bolt CMS – 3.6.4 – Cross-Site Scripting
The XSS vulnerability has been discovered in the Bolt CMS web application software due to its vulnerability in the source code in version 3.6.4. An attacker can exploit this vulnerability by sending a malicious HTTP POST request to the vulnerable application.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Bolt CMS.