Lucene search

K
osvGoogleOSV:GHSA-2G23-QMMP-FVMR
HistoryMay 24, 2022 - 5:05 p.m.

Bolt Cross-site Scripting via the slug, teaser or title parameters

2022-05-2417:05:27
Google
osv.dev
3
bolt content-editing xss
version 3.6.4
cross-site scripting
cve-2017-11128
cve-2018-19933

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

71.6%

Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

71.6%