LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://lavalite.com | not applicable |
https://i.ibb.co/34DSW7B/1.png | broken link |
https://i.ibb.co/kSkqPhQ/3.png | broken link |
https://i.ibb.co/mJq9CH8/2.png | broken link |
https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-27237 | third party advisory |