Medium severity5.3NVD Advisory· Published Dec 30, 2020· Updated Jun 17, 2026
CVE-2020-28925
CVE-2020-28925
Description
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bolt/boltPackagist | < 3.7.2 | 3.7.2 |
Affected products
3- Bolt/Boltdescription
Patches
Vulnerability mechanics
References
4- github.com/bolt/bolt/commit/c0cd530e78c2a8c6d71ceb75b10c251b39fb923anvdPatchThird Party AdvisoryWEB
- github.com/bolt/bolt/compare/3.7.1...3.7.2nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-w8cj-mvf9-mpc9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28925ghsaADVISORY
News mentions
0No linked articles in our index yet.