EIP-2026-109076
PRE-CVELavalite v9.0.0 - XSRF-TOKEN cookie File path traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109076. PoCs published by nu11secur1ty.
AI-analyzed exploit summary The exploit demonstrates a path traversal vulnerability in Lavalite CMS v9.0.0 via the XSRF-TOKEN cookie, allowing arbitrary file read access (e.g., /etc/passwd). The payload is embedded in the cookie, and the response confirms the vulnerability by returning the requested file.
Description
Lavalite v9.0.0 - XSRF-TOKEN cookie File path traversal
Exploits (1)
The exploit demonstrates a path traversal vulnerability in Lavalite CMS v9.0.0 via the XSRF-TOKEN cookie, allowing arbitrary file read access (e.g., /etc/passwd). The payload is embedded in the cookie, and the response confirms the vulnerability by returning the requested file.