PT-2026-44900 · Git · Bolt
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bolt CMS versions prior to 3.7.1
Description
An authenticated attacker with low-level privileges can perform SQL Injection via the
order parameter on content listing pages. This issue occurs within the OrderDirective component and can be used to extract sensitive information.Recommendations
Update Bolt CMS to version 3.7.1 or later.
As a temporary mitigation, restrict access to the content listing pages for low-privileged users.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bolt