MEDIUM5.4
GHSA-h7vh-6gmm-g7h9
Stored XSS in LavaLite 5.2.4
Details
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/lavalite/cms
Introduced in:
0No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.