Vulnerability Description
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Boltcms | Bolt | < 3.7.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/158299/Bolt-CMS-3.7.0-XSS-CSRF-Shell-UploadExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jul/4ExploitMailing ListThird Party Advisory
- https://github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419fPatchThird Party Advisory
- https://github.com/bolt/bolt/pull/7853PatchThird Party Advisory
- https://github.com/bolt/bolt/security/advisories/GHSA-2q66-6cc3-6xm8PatchThird Party Advisory
- http://packetstormsecurity.com/files/158299/Bolt-CMS-3.7.0-XSS-CSRF-Shell-UploadExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jul/4ExploitMailing ListThird Party Advisory
- https://github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419fPatchThird Party Advisory
- https://github.com/bolt/bolt/pull/7853PatchThird Party Advisory
- https://github.com/bolt/bolt/security/advisories/GHSA-2q66-6cc3-6xm8PatchThird Party Advisory
FAQ
What is CVE-2020-4040?
CVE-2020-4040 is a vulnerability with a CVSS score of 8.6 (HIGH). Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized...
How severe is CVE-2020-4040?
CVE-2020-4040 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-4040?
Check the references section above for vendor advisories and patch information. Affected products include: Boltcms Bolt.