Back to Database
Status published
Unknown
CVE-2022-42188
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path...
Vulnerability Description
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-42188
Credits & Attribution
No credits recorded in the NVD database.
More from lavalite
View All →CVE-2020-36397
A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact...
Medium
5.4
CVE-2020-36396
A stored cross site scripting (XSS) vulnerability in the /admin/roles/role...
Medium
5.4
CVE-2020-36395
A stored cross site scripting (XSS) vulnerability in the /admin/user/team...
Medium
5.4
CVE-2020-28124
Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address...
Medium
5.4
CVE-2020-23700
Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the...
Medium
4.8
Affected Vendor
lavalite
View all reports →Affected Software
lavalite
Vulnerable Versions:
9.0.0
Timeline
Official Publish:
October 18th, 2022
Last Modified:
May 13th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.