HIGH7.5
GHSA-cm22-88qr-7ffh
Lavalite vulnerable to Arbitrary File Read via Directory Traversal
Details
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/lavalite/cms
No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.