Описание
Gila CMS SQL Injection
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
Пакеты
Наименование
gilacms/gila
composer
Затронутые версииВерсия исправления
<= 1.15.4
Отсутствует
Связанные уязвимости
CVSS3: 3.8
nvd
около 2 лет назад
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.