Monthly Archive: July 2021

CVE-2020-23234

Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,". Date published : 2021-07-26 https://github.com/LavaLite/cms/issues/320