PT-2021-12038 · Lavalite · Lavalite
Songohan22
·
Published
2021-07-02
·
Updated
2022-05-24
·
CVE-2020-36396
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
LavaLite version 5.8.0
Description:
A stored cross site scripting (XSS) issue exists in the /admin/roles/role component, allowing authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the
New parameter.Recommendations:
For LavaLite version 5.8.0, consider restricting access to the /admin/roles/role component until a fix is available, and avoid using the
New parameter in this context to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lavalite