Vulnerability CVE-2022-42188


Published: 2022-10-18

Description:
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.

 References:
https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/LavaLite

Copyright 2026, cxsecurity.com

 

Back to Top