PT-2021-21869 · Gila Cms · Gila Cms
Published
2021-10-04
·
Updated
2022-05-03
·
CVE-2021-37777
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Gila CMS version 2.2.0
Description:
The issue allows thumbnails uploaded by one site owner to be visible to another site owner, potentially leading to sensitive information disclosure. This can be achieved by knowing the other site name and fuzzing for picture names.
Recommendations:
For Gila CMS version 2.2.0, consider restricting access to thumbnail uploads to prevent unauthorized viewing by other site owners. As a temporary workaround, restrict access to the thumbnail directory until a patch is available.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gila Cms