MEDIUM6.1
GHSA-94q4-v5g6-qp7x
LavaLite CMS vulnerable to host header injection attack
Details
LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/lavalite/cms
Introduced in:
0No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.