MEDIUM6.1
GHSA-5hcr-g32p-h74c
Lavalite CMS Cross Site Scripting vulnerability
Details
Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/lavalite/cms
No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.