CVE-2019-20803: XSS
Published May 21, 2020
·Updated
Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for gpreviewtheme.
Affected Software
1 affected component
GilaCMS Gila Cms<1.11.6
Event History
May 21, 2020
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-20803.
2
What is the affected software?
The affected software is Gila CMS before version 1.11.6.
3
What is the severity of CVE-2019-20803?
The severity of CVE-2019-20803 is medium with a CVSS score of 6.1.
4
How can the vulnerability be exploited?
The vulnerability can be exploited through reflected cross-site scripting (XSS) via the admin/content/postcategory id parameter.
5
Is there a fix available for this vulnerability?
Yes, a fix is available in version 1.11.6 of Gila CMS.