Lucene search

K
osvGoogleOSV:GHSA-GJX6-58XH-P7PW
HistoryMay 14, 2022 - 1:42 a.m.

Bolt Cross-site Scripting (XSS) via text input click preview button

2022-05-1401:42:52
Google
osv.dev
3
bolt cms
cross-site scripting
text input

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

71.6%

Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

71.6%