CVE-2019-11456: CSRF
Published Apr 22, 2019
·Updated
Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
Affected Software
1 affected component
GilaCMS Gila Cms=1.10.1
Event History
Apr 22, 2019
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
Description
Frequently Asked Questions
1
What is CVE-2019-11456?
CVE-2019-11456 is a vulnerability in Gila CMS 1.10.1 that allows fm/save CSRF for executing arbitrary PHP code.
2
How severe is CVE-2019-11456?
CVE-2019-11456 has a severity rating of 8.8 out of 10.
3
How does CVE-2019-11456 affect Gila CMS 1.10.1?
CVE-2019-11456 affects Gila CMS 1.10.1 by allowing fm/save CSRF for executing arbitrary PHP code.
4
How can I fix CVE-2019-11456?
To fix CVE-2019-11456, update Gila CMS to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2019-11456?
You can find more information about CVE-2019-11456 at https://cisk123456.blogspot.com/2019/04/gila-cms-1101-csrf.html.