CVE-2022-36532

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/09/2022
Last modified:
19/09/2022

Description

Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bolt:bolt_cms:*:*:*:*:*:*:*:* 5.1.12 (including)