CVE-2020-26623: SQL Injection
Published Jan 2, 2024
·Updated
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
Affected Software
2 affected components
composer/gilacms/gila<=1.15.4
GilaCMS Gila Cms<=1.15.4
Event History
Jan 2, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 3, 2024
Advisory Published
12:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2020-26623?
CVE-2020-26623 has been classified as a medium severity SQL Injection vulnerability.
2
How do I fix CVE-2020-26623?
To fix CVE-2020-26623, upgrade Gila CMS to version 1.15.5 or later.
3
What versions of Gila CMS are affected by CVE-2020-26623?
CVE-2020-26623 affects Gila CMS versions 1.15.4 and earlier.
4
Can CVE-2020-26623 lead to remote code execution?
Yes, CVE-2020-26623 allows a remote attacker to execute arbitrary web scripts.
5
What component of Gila CMS is vulnerable in CVE-2020-26623?
The vulnerability is found in the Area parameter under the Administration>Widget tab.