Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25643
HistoryJun 10, 2020 - 3:26 a.m.

Cross-site Request Forgery (CSRF)

2020-06-1003:26:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.003

Percentile

69.2%

bolt/bolt is vulnerable to cross-site request forgery. The vulnerability exists as it accepts requests without a valid token in the preview generating endpoint in src/Controller/Frontend.php which allows an attacker to inject and execute arbitrary javascript.

EPSS

0.003

Percentile

69.2%