← Back to CVE List
CVE-2017-16754
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt