Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Honnycyo

#47325of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2018-13627
5.4
2018-09-05
Lavalite · Lavalite · CVE-2018-16551
**Name of the Vulnerable Software and Affected Versions** LavaLite version 5.5 **Description** The issue is related to a Cross-Site Scripting (XSS) problem. It can be triggered via the `/edit` URI, as demonstrated by the example `client/job/job/Zy8PWBekrJ/edit`. **Recommendations** For LavaLite version 5.5, consider restricting access to the `/edit` URI until a patch is available. As a temporary workaround, avoid using the `/edit` endpoint to minimize the risk of exploitation.