PT-2018-5234 · Lavalite · Lavalite
Prodigysml
·
Published
2018-01-03
·
Updated
2022-05-14
·
CVE-2017-1000467
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LavaLite version 5.2.4
Description
The issue concerns a stored cross-site scripting vulnerability within the blog creation page. This can lead to disruption of service and allow the execution of javascript code.
Recommendations
For LavaLite version 5.2.4, consider disabling the blog creation page until a patch is available to prevent potential exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lavalite