CVE-2015-7309
Bolt < 2.2.0 - Injection
Title source: ruleDescription
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38196
metasploit
WORKING POC
EXCELLENT
by Tim Coen · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/bolt_file_upload.rb
References (6)
Scores
EPSS
0.6027
EPSS Percentile
98.3%
Details
CWE
CWE-74
Status
published
Products (1)
boltcms/bolt
< 2.2.0
Published
Sep 22, 2015
Tracked Since
Feb 18, 2026