MEDIUM4.8
GHSA-v2f3-f8x4-m3w8
Cross Site Scripting in LavaLite CMS
Details
Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/lavalite/cms
Introduced in:
0No fixed version published yet for lavalite/cms (composer). Pin to a known-safe version or switch to an alternative.