VDB
Sign up
HIGH7.5

GHSA-cm22-88qr-7ffh

Lavalite vulnerable to Arbitrary File Read via Directory Traversal

Details

In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/lavalite/cms

No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.

References