High severity8.6NVD Advisory· Published Jun 8, 2020· Updated Jun 17, 2026
CVE-2020-4040
CVE-2020-4040
Description
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bolt/boltPackagist | < 3.7.1 | 3.7.1 |
Affected products
3Patches
Vulnerability mechanics
References
7- github.com/bolt/bolt/commit/b42cbfcf3e3108c46a80581216ba03ef449e419fnvdPatchThird Party AdvisoryWEB
- github.com/bolt/bolt/pull/7853nvdPatchThird Party AdvisoryWEB
- github.com/bolt/bolt/security/advisories/GHSA-2q66-6cc3-6xm8nvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/158299/Bolt-CMS-3.7.0-XSS-CSRF-Shell-Upload.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2020/Jul/4nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-2q66-6cc3-6xm8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-4040ghsaADVISORY
News mentions
0No linked articles in our index yet.