Description
Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5hcr-g32p-h74c | Lavalite CMS Cross Site Scripting vulnerability |
References
| Link | Providers |
|---|---|
| https://jinmu1108.github.io/uncategorized/CVE-2024-31828/ |
|
History
Fri, 18 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lavalite
Lavalite lavalite |
|
| CPEs | cpe:2.3:a:lavalite:lavalite:10.1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Lavalite
Lavalite lavalite |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T01:59:50.639Z
Reserved: 2024-04-05T00:00:00.000Z
Link: CVE-2024-31828
Updated: 2024-08-02T01:59:50.639Z
Status : Analyzed
Published: 2024-04-26T22:15:08.200
Modified: 2025-04-18T18:43:20.300
Link: CVE-2024-31828
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA