The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.
| Software | From | Fixed in |
|---|---|---|
| boltcms / bolt | - | 2.2.0.x |