CVE-2020-7370
MEDIUMBoltbrowser Bolt Browser < 1.4 - Missing Authentication
Title source: ruleDescription
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Bolt Browser version 1.4 and prior versions.
Scores
CVSS v3
4.3
EPSS
0.0019
EPSS Percentile
41.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Details
CWE
CWE-451
CWE-306
Status
published
Products (1)
boltbrowser/bolt_browser
< 1.4
Published
Oct 20, 2020
Tracked Since
Feb 18, 2026