CVE-2021-39486: XSS
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39486?
CVE-2021-39486 is a vulnerability in Gila CMS version 2.2.0 that allows an attacker to perform a stored cross-site scripting (XSS) attack through a malicious file upload.
How does CVE-2021-39486 work?
CVE-2021-39486 allows an attacker to upload a malicious file to the vulnerable Gila CMS, which can be used to steal user cookies, passwords, or execute arbitrary code on the victim's browser.
What is the severity of CVE-2021-39486?
CVE-2021-39486 has a severity rating of 5.4 (medium).
How can I fix CVE-2021-39486?
To fix CVE-2021-39486, it is recommended to update Gila CMS to a version that is not affected by the vulnerability, or apply any available patches or security updates provided by the vendor.
Where can I find more information about CVE-2021-39486?
More information about CVE-2021-39486 can be found at the following reference: https://www.navidkagalwalla.com/gila-cms-vulnerabilities