CVE-2020-20696: XSS
Published Sep 27, 2021
·Updated
A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.
Affected Software
1 affected component
GilaCMS Gila Cms=1.11.4
Event History
Sep 27, 2021
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-20696.
2
What is the severity of CVE-2020-20696?
The severity of CVE-2020-20696 is medium, with a severity value of 5.4.
3
What is affected by CVE-2020-20696?
GilaCMS v1.11.4 is affected by CVE-2020-20696.
4
What is the description of CVE-2020-20696?
CVE-2020-20696 is a cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 that allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.
5
Is there a fix available for CVE-2020-20696?
Currently, there is no information available about a fix for CVE-2020-20696. It is recommended to follow the official GitHub repository of GilaCMS for updates and patches.