CVE-2020-36397

Cross-site Scripting in packagist/lavalite/cms

Identifier

CVE-2020-36397

Package Slug

packagist/lavalite/cms

Vulnerability

Cross-site Scripting

Description

A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the New parameter.

Affected Versions

Version 5.8.0

Solution

Upgrade to version 7.0.1 or above.

Last Modified

2021-07-08

source