{"id":"GHSA-5r9j-698h-2h5m","summary":"Bolt stored Cross-site Scripting (XSS)","details":"Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.","aliases":["CVE-2017-11128"],"modified":"2024-04-23T23:42:48.848913Z","published":"2022-05-17T02:27:47Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-23T23:15:45Z","nvd_published_at":"2017-07-17T19:29:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11128"},{"type":"PACKAGE","url":"https://github.com/bolt/bolt"},{"type":"WEB","url":"https://websecnerd.blogspot.in/2017/07/bolt-cms-3.html"}],"affected":[{"package":{"name":"bolt/bolt","ecosystem":"Packagist","purl":"pkg:composer/bolt/bolt"},"versions":["3.2.14"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5r9j-698h-2h5m/GHSA-5r9j-698h-2h5m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}