You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I found a sXss vulnerability in the latest version of LavaLite CMS:
Users can create a malicious Blog Tittle that triggers malicious code when an administrator accesses the blog admin panel.
I found a sXss vulnerability in the latest version of LavaLite CMS:
Users can create a malicious Blog Tittle that triggers malicious code when an administrator accesses the blog admin panel.
Exp:
Poc:
Triggered when an administrator visits the blog admin page:
Affect:
Without httponly set, an attacker can steal the identity of an administrator or execute other malicious code.
The text was updated successfully, but these errors were encountered: