First published: Mon Jan 06 2020(Updated: )
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.11.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5515 is a vulnerability in Gila CMS 1.11.8 that allows SQL Injection through the /admin/sql?query= parameter.
CVE-2020-5515 has a severity rating of 7.2 (high).
Gila CMS 1.11.8 is affected by CVE-2020-5515.
To fix CVE-2020-5515, it is recommended to update Gila CMS to a patched version or apply the necessary security patches provided by the vendor.
Yes, you can find more information about CVE-2020-5515 through the provided references: [Reference 1](http://packetstormsecurity.com/files/158114/Gila-CMS-1.11.8-SQL-Injection.html), [Reference 2](http://packetstormsecurity.com/files/158140/Gila-CMS-1.1.18.1-SQL-Injection-Shell-Upload.html), [Reference 3](https://infosecdb.wordpress.com/2020/01/05/gilacms-1-11-8-admin-sqlquery-sql-injection/).