Lucene search

K
osvGoogleOSV:GHSA-GMG5-F2GM-P3H7
HistoryMay 13, 2022 - 1:12 a.m.

Bolt Unrestricted Upload of File with Dangerous Type

2022-05-1301:12:17
Google
osv.dev
5
bolt
file upload
remote code execution
security vulnerability
php file

AI Score

7.8

Confidence

High

EPSS

0.006

Percentile

79.6%

Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.

AI Score

7.8

Confidence

High

EPSS

0.006

Percentile

79.6%