CVE-2022-31321
Critical · CVSS 9.1Bolt CMS — Improper Input Validation - Directory Enumeration / Denial of Service (DoS)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-20
Description
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
Search profile — drives PoC discovery
Symbols foldernamefoldername parameterdirectory enumerationDoScrafted input
Keywords CVE-2022-31321Bolt CMSBolt 5.1.7foldernamedirectory enumerationinput validationDoSCWE-20AARO-Bugs
Versions: 5.1.7
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z