CVE-2020-23234

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-23234
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-23234.json
Aliases
Published
2021-07-26T20:15:08Z
Modified
2023-11-29T08:13:48.126089Z
Details

Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".

References

Affected packages

Git / github.com/lavalite/cms

Affected ranges

Type
GIT
Repo
https://github.com/lavalite/cms
Events
Introduced
0The exact introduced commit is unknown
Last affected

Affected versions

5.*

5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.5.7
5.5.8
5.5.9
5.6.1
5.6.2
5.7.0
5.7.1
5.7.2
5.7.3
5.7.4

v5.*

v5.0.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.2.3
v5.2.4
v5.3.0
v5.3.1
v5.3.2
v5.3.3
v5.3.4
v5.3.5
v5.3.6
v5.3.7
v5.4.0
v5.4.1
v5.4.2
v5.4.3
v5.4.4
v5.4.5
v5.8.0