VDB
Sign up
MEDIUM6.1

GHSA-5hcr-g32p-h74c

Lavalite CMS Cross Site Scripting vulnerability

Details

Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/lavalite/cms

No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.

References