LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLavalite
APPLavalite10.1.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2023-27238CRITICAL9.8PL ✓ten sam produkt
Web Cache Poisoning w LavaLite CMS 9.0.0
CVE-2023-36983HIGH7.5ten sam produkt
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36984HIGH7.5ten sam produkt
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2022-42188HIGH7.5ten sam produkt
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbi...
CVE-2025-71177MEDIUM5.1ten sam produkt
LavaLite CMS w wersjach do 10.1.0 zawiera podatność stored XSS w funkcjonalności tworzenia pakietów i wyszukiw...