The theme editor in Bolt before 2.2.5 does not check the...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Sep 22, 2015
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.
References