A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument title/textarea leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.
Metrics
Affected Vendors & Products
References
History
Mon, 19 Aug 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument textarea leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273168. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life. | A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument title/textarea leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life. |
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2024-07-31T07:00:06.610Z
Updated: 2024-08-19T13:34:37.679Z
Reserved: 2024-07-30T15:33:30.302Z
Link: CVE-2024-7300
Vulnrichment
Updated: 2024-07-31T13:55:27.339Z
NVD
Status : Awaiting Analysis
Published: 2024-07-31T07:15:02.760
Modified: 2024-08-19T14:15:23.360
Link: CVE-2024-7300
Redhat
No data.