{"id":"CVE-2019-9185","aliases":["GHSA-gmg5-f2gm-p3h7"],"url":"https://o3.security/vulnerability/CVE-2019-9185","summary":"Bolt Unrestricted Upload of File with Dangerous Type","details":"Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.","published":"2019-03-07T23:29:02.097Z","modified":"2026-08-07T16:35:37.382508Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.02274,"percentile":0.81599,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"bolt/bolt","fixedVersion":"3.6.5"}],"fix":{"url":"https://github.com/bolt/bolt/pull/7745","label":"bolt/bolt#7745"},"references":[{"type":"ADVISORY","url":"https://github.com/bolt/bolt/blob/v3.6.5/changelog.md"},{"type":"ADVISORY","url":"https://github.com/bolt/bolt/pull/7745"},{"type":"FIX","url":"https://github.com/bolt/bolt/releases/tag/v3.6.5"},{"type":"EVIDENCE","url":"https://www.hacksecproject.com/?p=293"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:35:37.382508Z"}}