MEDIUM5.4
GHSA-pxxp-283v-xpq5
Stored XSS in LavaLite 5.5
Details
LavaLite 5.5 has XSS via a `/edit` URI, as demonstrated by `client/job/job/Zy8PWBekrJ/edit`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/lavalite/cms
Introduced in:
0No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.