Vulnerability Description
In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javascript code in the file name when creating/uploading the file. But, once created/uploaded, it can be renamed to inject the payload in it. Additionally, the measures to prevent renaming the file to disallowed filename extensions could be circumvented. This is fixed in Bolt 3.7.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Boltcms | Bolt | < 3.7.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/158299/Bolt-CMS-3.7.0-XSS-CSRF-Shell-UploadExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jul/4ExploitMailing ListThird Party Advisory
- https://github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419fPatchThird Party Advisory
- https://github.com/bolt/bolt/pull/7853PatchThird Party Advisory
- https://github.com/bolt/bolt/security/advisories/GHSA-68q3-7wjp-7q3jPatchThird Party Advisory
- http://packetstormsecurity.com/files/158299/Bolt-CMS-3.7.0-XSS-CSRF-Shell-UploadExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jul/4ExploitMailing ListThird Party Advisory
- https://github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419fPatchThird Party Advisory
- https://github.com/bolt/bolt/pull/7853PatchThird Party Advisory
- https://github.com/bolt/bolt/security/advisories/GHSA-68q3-7wjp-7q3jPatchThird Party Advisory
FAQ
What is CVE-2020-4041?
CVE-2020-4041 is a vulnerability with a CVSS score of 7.4 (HIGH). In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javascript code in the file name when creating/uploading the file. But, once...
How severe is CVE-2020-4041?
CVE-2020-4041 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-4041?
Check the references section above for vendor advisories and patch information. Affected products include: Boltcms Bolt.