Home / os / winnt

Bolt CMS 3.7.0 Authenticated Remote Code Execution

Posted on 29 June 2020

This Metasploit module exploits multiple vulnerabilities in Bolt CMS version 3.7.0 and 3.6.x in order to execute arbitrary commands as the user running Bolt. Valid credentials for a Bolt CMS user are required. This module has been successfully tested against Bolt CMS 3.7.0 running on CentOS 7.

 

TOP