CVE-2015-7309

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
22/09/2015
Last modified:
12/04/2025

Description

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:boltcms:bolt:*:*:*:*:*:*:*:* 2.2.0 (including)