CVE-2021-37777: High severity GilaCMS Gila Cms vulnerability
Published Oct 4, 2021
·Updated
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive information disclosure.
Affected Software
1 affected component
GilaCMS Gila Cms=2.2.0
Event History
Oct 4, 2021
CVE Published
via MITRE·01:40 PM
Data Sourced
via MITRE·01:40 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software