cve/2020/CVE-2020-4040.md
2024-05-25 21:48:12 +02:00

1.2 KiB

CVE-2020-4040

Description

Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1

POC

Reference

Github