PT-2026-4499 · Unknown · Lavalite Cms

Abigowl

·

Publicado

2026-01-23

·

Atualizado

2026-01-24

·

CVE-2025-71177

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LavaLite CMS versions up to and including 10.1.0
Description LavaLite CMS is affected by a stored cross-site scripting issue in the package creation and search functionality. Authenticated users can inject crafted HTML or JavaScript into the Name or Description fields during package creation. This malicious content is stored and subsequently displayed without proper output encoding when other users view package search results, leading to script execution in their browsers. This could allow for session hijacking, credential theft, and unauthorized actions.
Recommendations Versions prior to 10.1.0 should be updated.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-71177
GHSA-W7RQ-FGX4-4XCM

Produtos afetados

Lavalite Cms