Description
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0450 | Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1 |
Github GHSA |
GHSA-2q66-6cc3-6xm8 | CSRF issue on preview pages in Bolt CMS |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T07:52:20.663Z
Reserved: 2019-12-30T00:00:00.000Z
Link: CVE-2020-4040
No data.
Status : Modified
Published: 2020-06-08T22:15:10.603
Modified: 2024-11-21T05:32:12.237
Link: CVE-2020-4040
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA