Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. lavalite/cms
  4. ›
  5. CVE-2020-23234

CVE-2020-23234: Cross-site Scripting

July 26, 2021 (updated July 30, 2021)

Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as “ontoggle,”.

References

  • nvd.nist.gov/vuln/detail/CVE-2020-23234

Code Behaviors & Features

Detect and mitigate CVE-2020-23234 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

Version 5.8.0

Fixed versions

  • 7.0.1

Solution

Upgrade to version 7.0.1 or above.

Impact 4.8 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Source file

packagist/lavalite/cms/CVE-2020-23234.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:27 +0000.