CVE-2019-17535: XSS
Published Oct 13, 2019
·Updated
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.
Affected Software
1 affected component
GilaCMS Gila Cms<=1.11.4
Remediation
Patch Available
Event History
Oct 13, 2019
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2019-17535?
CVE-2019-17535 is a vulnerability in Gila CMS through version 1.11.4 that allows for XSS (Cross-Site Scripting) attacks via the search parameter in the blog-list.php file.
2
How severe is CVE-2019-17535?
CVE-2019-17535 has a severity rating of 6.1 (critical).
3
What is the affected software of CVE-2019-17535?
The affected software is Gila CMS version 1.11.4.
4
How can I exploit CVE-2019-17535?
Exploiting CVE-2019-17535 involves injecting malicious scripts into the search parameter of the blog-list.php file in Gila CMS.
5
How can I fix CVE-2019-17535?
To fix CVE-2019-17535, update Gila CMS to a version higher than 1.11.4 and ensure that input in the search parameter is properly sanitized.