LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLavalite
APPLavalite10.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-27238CRITICAL9.8PL ✓same product
Web Cache Poisoning w LavaLite CMS 9.0.0
CVE-2023-36983HIGH7.5same product
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36984HIGH7.5same product
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2022-42188HIGH7.5same product
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbi...
CVE-2025-71177MEDIUM5.1same product
LavaLite CMS w wersjach do 10.1.0 zawiera podatność stored XSS w funkcjonalności tworzenia pakietów i wyszukiw...