VDB
Sign up
MEDIUM4.8

GHSA-v2f3-f8x4-m3w8

Cross Site Scripting in LavaLite CMS

Details

Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/lavalite/cms
Introduced in: 0

No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.

References