First published: Mon Sep 27 2021(Updated: )
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20693 is a Cross-Site Request Forgery (CSRF) vulnerability in GilaCMS v1.11.4 that allows authenticated attackers to add administrator accounts.
CVE-2020-20693 has a severity rating of 8.8 (high).
GilaCMS v1.11.4 is affected by CVE-2020-20693.
To fix CVE-2020-20693, update GilaCMS to a version that is not affected by the vulnerability.
You can find more information about CVE-2020-20693 at the following link: [https://github.com/GilaCMS/gila/issues/51]