Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-10874

Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.1%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2019-10874
  • Boltcms » Bolt » Version: 3.6.6
    cpe:2.3:a:boltcms:bolt:3.6.6


Contact Us

Shodan ® - All rights reserved