Remote Code Execution Vulnerability in Bolt CMS by Bolt
CVE-2021-40219
8.8HIGH
What is CVE-2021-40219?
Bolt CMS versions up to 4.2 are susceptible to a Remote Code Execution vulnerability due to unsafe theme rendering practices. An authenticated attacker can exploit this flaw by modifying the theme to inject server-side template commands, ultimately leading to unauthorized code execution on the server. This significant security weakness emphasizes the need for users to update their installations and follow best security practices to mitigate potential threats.
