First published: Mon Sep 27 2021(Updated: )
A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-20696.
The severity of CVE-2020-20696 is medium, with a severity value of 5.4.
GilaCMS v1.11.4 is affected by CVE-2020-20696.
CVE-2020-20696 is a cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 that allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.
Currently, there is no information available about a fix for CVE-2020-20696. It is recommended to follow the official GitHub repository of GilaCMS for updates and patches.