High severity7.5NVD Advisory· Published Oct 18, 2022· Updated Jun 17, 2026
CVE-2022-42188
CVE-2022-42188
Description
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- ghsa-coords
Patches
Vulnerability mechanics
References
3- github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/LavaLitenvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-cm22-88qr-7ffhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-42188ghsaADVISORY
News mentions
0No linked articles in our index yet.