Lucene search

K
osvGoogleOSV:GHSA-W8CJ-MVF9-MPC9
HistoryMay 06, 2021 - 6:53 p.m.

OS Command injection in Bolt

2021-05-0618:53:29
Google
osv.dev
3
bolt
command injection
twig
security guidance
php

EPSS

0.001

Percentile

30.9%

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the “How to Harden Your PHP for Better Security” guidance.

EPSS

0.001

Percentile

30.9%