First published: Tue Jan 02 2024(Updated: )
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/gilacms/gila | <=1.15.4 | |
Tina Tinacms | <=1.15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26623 has been classified as a medium severity SQL Injection vulnerability.
To fix CVE-2020-26623, upgrade Gila CMS to version 1.15.5 or later.
CVE-2020-26623 affects Gila CMS versions 1.15.4 and earlier.
Yes, CVE-2020-26623 allows a remote attacker to execute arbitrary web scripts.
The vulnerability is found in the Area parameter under the Administration>Widget tab.