VDB
Sign up
HIGH8.6

GHSA-2q66-6cc3-6xm8

CSRF issue on preview pages in Bolt CMS

Quick fix

GHSA-2q66-6cc3-6xm8 — bolt/bolt: upgrade to the fixed version with the command below.

composer require bolt/bolt:^3.7.1

Details

### Impact

Bolt CMS lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview.

### Patches

This has been fixed in Bolt 3.7.1

### References

Related issue: https://github.com/bolt/bolt/pull/7853

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/bolt/bolt
Introduced in: 0Fixed in: 3.7.1
Fixcomposer require bolt/bolt:^3.7.1

References