PT-2021-21869 · Gila Cms · Gila Cms

Published

2021-10-04

·

Updated

2022-05-03

·

CVE-2021-37777

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Gila CMS version 2.2.0
Description: The issue allows thumbnails uploaded by one site owner to be visible to another site owner, potentially leading to sensitive information disclosure. This can be achieved by knowing the other site name and fuzzing for picture names.
Recommendations: For Gila CMS version 2.2.0, consider restricting access to thumbnail uploads to prevent unauthorized viewing by other site owners. As a temporary workaround, restrict access to the thumbnail directory until a patch is available.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37777

Affected Products

Gila Cms