PT-2020-10773 · Gila · Gila Cms

Frostnull

·

Published

2020-05-21

·

Updated

2022-10-06

·

CVE-2019-20803

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gila CMS versions prior to 1.11.6
Description The issue is related to reflected XSS, which occurs via the id parameter in the admin/content/postcategory endpoint. This parameter is mishandled when g preview theme is used.
Recommendations For versions prior to 1.11.6, update to version 1.11.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin/content/postcategory endpoint until the update is applied. Avoid using the id parameter in this endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-20803

Affected Products

Gila Cms