VDB
Sign up
MEDIUM5.4

GHSA-3cfg-rxh6-h2rh

LavaLite Stored Cross-site Scripting vulnerability

Details

A stored cross site scripting (XSS) vulnerability in the `/admin/contact/contact` component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the `New` parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/lavalite/cms
Introduced in: 0

No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.

References