CVE-2020-26624: SQL Injection
Published Jan 2, 2024
·Updated
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
Affected Software
1 affected component
GilaCMS Gila Cms<=1.15.4
Event History
Jan 2, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-26624?
CVE-2020-26624 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2020-26624?
To fix CVE-2020-26624, update Gila CMS to version 1.15.5 or later.
3
What systems are affected by CVE-2020-26624?
CVE-2020-26624 affects Gila CMS version 1.15.4 and earlier.
4
What does CVE-2020-26624 allow an attacker to do?
CVE-2020-26624 allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
5
Is there a workaround for CVE-2020-26624 if I can't update?
There is no officially recommended workaround for CVE-2020-26624, so upgrading is strongly advised.