Vulnerability Description
Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lavalite | Lavalite | 5.8.0 |
Related Weaknesses (CWE)
References
- https://github.com/LavaLite/cms/issues/320ExploitThird Party Advisory
- https://github.com/LavaLite/cms/issues/320ExploitThird Party Advisory
FAQ
What is CVE-2020-23234?
CVE-2020-23234 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
How severe is CVE-2020-23234?
CVE-2020-23234 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23234?
Check the references section above for vendor advisories and patch information. Affected products include: Lavalite Lavalite.