Vulnerability Description
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gilacms | Gila Cms | <= 1.15.4 |
Related Weaknesses (CWE)
References
- http://gilacms.comProduct
- https://github.com/GilaCMS/gilaProduct
- https://github.com/GilaCMS/gila/security/policyVendor Advisory
- https://packetstormsecurity.com/files/176301/GilaCMS-1.15.4-SQL-Injection.htmlExploitThird Party AdvisoryVDB Entry
- http://gilacms.comProduct
- https://github.com/GilaCMS/gilaProduct
- https://github.com/GilaCMS/gila/security/policyVendor Advisory
- https://packetstormsecurity.com/files/176301/GilaCMS-1.15.4-SQL-Injection.htmlExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-26624?
CVE-2020-26624 is a vulnerability with a CVSS score of 3.8 (LOW). A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
How severe is CVE-2020-26624?
CVE-2020-26624 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26624?
Check the references section above for vendor advisories and patch information. Affected products include: Gilacms Gila Cms.