First published: Tue Jan 02 2024(Updated: )
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | <=1.15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26625 is categorized as a critical vulnerability due to its SQL injection nature.
To mitigate CVE-2020-26625, update Gila CMS to version 1.15.5 or later.
CVE-2020-26625 affects Gila CMS versions up to and including 1.15.4.
CVE-2020-26625 can allow remote attackers to execute arbitrary web scripts through SQL injection.
To identify if your system is vulnerable to CVE-2020-26625, check for the presence of Gila CMS versions before 1.15.5.