VDB
Sign up
MEDIUM5.4

GHSA-h7vh-6gmm-g7h9

Stored XSS in LavaLite 5.2.4

Details

LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/lavalite/cms
Introduced in: 0

No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.

References