CVE-2025-70866 | LavaLite CMS up to 10.1.0 Role-Based Access Control /admin/login access control
A vulnerability was found in LavaLite CMS up to 10.1.0. It has been rated as critical. This affects an unknown function of the file /admin/login of the component Role-Based Access Control. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-70866. The attack is possible to be carried out remotely. No exploit exists.