-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
While no specific code is available, Host Header Injection vulnerabilities typically occur in: 1) Entry controllers handling request processing 2) Middleware handling request context setup. The XSS manifestation (CWE-79) suggests unsanitized header values flow into rendered content. PublicController is a logical entry point for frontend requests, and middleware commonly handles header processing. Confidence is medium due to pattern matching with typical PHP CMS architectures and the vulnerability type described.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| lavalite/cms | composer | <= 9.0.0 |
Ongoing coverage of React2Shell