VDB
Sign up
HIGH8.8

GHSA-gprh-7767-cw39

Code Injection in Bolt CMS

Details

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/bolt/core
Introduced in: 0

No fixed version published yet for bolt/core (composer). Pin to a known-safe version or switch to an alternative.

References