CVE-2020-20695: XSS
Published Sep 27, 2021
·Updated
A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
Affected Software
1 affected component
GilaCMS Gila Cms=1.11.4
Event History
Sep 27, 2021
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
Description
Frequently Asked Questions
1
What is CVE-2020-20695?
CVE-2020-20695 is a stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4.
2
How does CVE-2020-20695 affect GilaCMS?
CVE-2020-20695 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file in GilaCMS v1.11.4.
3
What is the severity of CVE-2020-20695?
The severity of CVE-2020-20695 is medium, with a CVSS score of 5.4.
4
How can I fix CVE-2020-20695 in GilaCMS?
To fix CVE-2020-20695 in GilaCMS, update to version 1.11.5 or later, as this vulnerability is patched in later versions.
5
Where can I find more information about CVE-2020-20695?
More information about CVE-2020-20695 can be found at the following reference: - [GitHub Issue](https://github.com/GilaCMS/gila/issues/52)