Lucene search

K
osvGoogleOSV:CVE-2021-40219
HistoryApr 11, 2022 - 5:15 p.m.

CVE-2021-40219

2022-04-1117:15:08
Google
osv.dev
6
bolt cms
remote code execution
theme rendering
authenticated attacker
server-side template injection
software vulnerability

AI Score

9.2

Confidence

High

EPSS

0.074

Percentile

94.2%

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.

AI Score

9.2

Confidence

High

EPSS

0.074

Percentile

94.2%

Related for OSV:CVE-2021-40219