Vulnerability Description
Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bolt | Bolt Cms | <= 4.2.0 |
Related Weaknesses (CWE)
References
- http://boltcms.comVendor Advisory
- https://github.com/bolt/coreThird Party Advisory
- https://github.com/bolt/core/blob/3b21a73ebf519b76756d3ad2841312d10ef11461/src/CExploitThird Party Advisory
- https://github.com/iiSiLvEr/CVEs/tree/main/CVE-2021-40219ExploitThird Party Advisory
- http://boltcms.comVendor Advisory
- https://github.com/bolt/coreThird Party Advisory
- https://github.com/bolt/core/blob/3b21a73ebf519b76756d3ad2841312d10ef11461/src/CExploitThird Party Advisory
- https://github.com/iiSiLvEr/CVEs/tree/main/CVE-2021-40219ExploitThird Party Advisory
FAQ
What is CVE-2021-40219?
CVE-2021-40219 is a vulnerability with a CVSS score of 8.8 (HIGH). Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code executi...
How severe is CVE-2021-40219?
CVE-2021-40219 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40219?
Check the references section above for vendor advisories and patch information. Affected products include: Bolt Bolt Cms.