Bolt CMS
cpe:2.3:a:bolt:bolt_cms:*:*:*:*:*:*:*, +1 more
- 3.7.0
A SQL injection vulnerability has been identified in Bolt CMS versions through 3.7.0. The issue resides in the 'order' parameter of the content listing pages, specifically within the OrderDirective component. This vulnerability allows authenticated attackers with low-level privileges to exploit the parameter, leading to the extraction of sensitive information from the database.
Exploitation of this vulnerability could result in unauthorized access to sensitive database information, including administrative password hashes, and potentially allow for a complete database compromise.
To reproduce this vulnerability, log into the Bolt CMS backend with a low-privileged account, such as an Editor. Then, navigate to the content overview pages and inject a time-based SQL payload into the 'order' parameter. If successful, a delay in the server response time will indicate that the SQL injection has been exploited.
Users are advised to update to Bolt CMS version 3.7.1 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.