CVE-2020-20692: SQL Injection
Published Sep 27, 2021
·Updated
GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $GET parameter in /src/core/controllers/cm.php.
Affected Software
1 affected component
GilaCMS Gila Cms=1.11.4
Event History
Sep 27, 2021
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
Description
Frequently Asked Questions
1
What is CVE-2020-20692?
CVE-2020-20692 is the identifier for a SQL injection vulnerability found in GilaCMS v1.11.4.
2
How severe is CVE-2020-20692?
CVE-2020-20692 has a severity rating of 7.2 out of 10, which is considered high.
3
How does CVE-2020-20692 affect GilaCMS?
CVE-2020-20692 affects GilaCMS version 1.11.4.
4
How can I fix CVE-2020-20692?
To fix CVE-2020-20692, update GilaCMS to a version that is not affected by the vulnerability.
5
What is CWE-89?
CWE-89 is a Common Weakness Enumeration identifier for the SQL injection vulnerability.