First published: Tue Jan 02 2024(Updated: )
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | <=1.15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26624 is classified as a critical SQL injection vulnerability.
To fix CVE-2020-26624, update Gila CMS to version 1.15.5 or later.
CVE-2020-26624 affects Gila CMS version 1.15.4 and earlier.
CVE-2020-26624 allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
There is no officially recommended workaround for CVE-2020-26624, so upgrading is strongly advised.