CVE-2019-20804: XSS
Published May 21, 2020
·Updated
Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
Affected Software
1 affected component
GilaCMS Gila Cms<1.11.6
Event History
May 21, 2020
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-20804.
2
What is the severity of CVE-2019-20804?
The severity of CVE-2019-20804 is high with a CVSS score of 8.8.
3
How does CVE-2019-20804 affect Gila CMS?
CVE-2019-20804 affects Gila CMS versions before 1.11.6.
4
What is the impact of CVE-2019-20804?
CVE-2019-20804 allows CSRF attacks with resultant XSS, leading to compromise of the admin account.
5
How can I fix CVE-2019-20804?
To fix CVE-2019-20804, update Gila CMS to version 1.11.6 or higher.