CVE-2017-16754

Published: Nov 10, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2022-5624 Aliases: GHSA-wr23-m9m2-jjf4
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
MEDIUM 5,0
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: none
Availability: none

Description

AI Translation Available

Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0038
Percentile
0,6th
Updated

EPSS Score Trend (Last 90 Days)

732

Incorrect Permission Assignment for Critical Resource

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Access Control Integrity Other
Potential Impacts:
Read Application Data Read Files Or Directories Gain Privileges Or Assume Identity Modify Application Data Other
Applicable Platforms
Technologies: Not Technology-Specific, Cloud Computing
View CWE Details
Application

Bolt by Boltcms

Version Range Affected
To 3.3.5 (inclusive)
cpe:2.3:a:boltcms:bolt:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/bolt/bolt/commit/aa21787241945457a2e4abc8b079672935fe0840
https://github.com/bolt/bolt/releases/tag/v3.3.6
Release Notes Third Party Advisory
https://github.com/bolt/bolt/releases/tag/v3.3.6
http://www.securityfocus.com/bid/101777
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/101777
https://github.com/bolt/bolt/commit/aa21787241945457a2e4abc8b079672935fe0840
https://github.com/bolt/bolt/releases/tag/v3.3.6
Release Notes Third Party Advisory
https://github.com/bolt/bolt/releases/tag/v3.3.6
http://www.securityfocus.com/bid/101777
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/101777