Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based access control verification.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lavalite CMS 安全漏洞
Vulnerability Description
Lavalite CMS是一套基于PHP的开源内容管理系统(CMS)。 LavaLite CMS 10.1.0版本存在安全漏洞,该漏洞源于访问控制不当,可能导致低权限用户直接访问管理后台。
CVSS Information
N/A
Vulnerability Type
N/A