First published: Mon Sep 27 2021(Updated: )
GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20692 is the identifier for a SQL injection vulnerability found in GilaCMS v1.11.4.
CVE-2020-20692 has a severity rating of 7.2 out of 10, which is considered high.
CVE-2020-20692 affects GilaCMS version 1.11.4.
To fix CVE-2020-20692, update GilaCMS to a version that is not affected by the vulnerability.
CWE-89 is a Common Weakness Enumeration identifier for the SQL injection vulnerability.