CVE-2022-42188
18.10.2022, 19:15
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
Vendor | Product | Version |
---|---|---|
lavalite | lavalite | 9.0.0 |
𝑥
= Vulnerable software versions
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
Vendor | Product | Version |
---|---|---|
lavalite | lavalite | 9.0.0 |