Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown

CVE-2024-7657

Disclosure Date: August 12, 2024 (last updated August 16, 2024)
A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2020-26625

Disclosure Date: January 02, 2024 (last updated January 10, 2024)
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
Attacker Value
Unknown

CVE-2020-26624

Disclosure Date: January 02, 2024 (last updated January 09, 2024)
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
Attacker Value
Unknown

CVE-2020-26623

Disclosure Date: January 02, 2024 (last updated January 09, 2024)
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
Attacker Value
Unknown

CVE-2020-20523

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to execute arbitrary code during the Gila CMS installation.
Attacker Value
Unknown

CVE-2020-20726

Disclosure Date: June 20, 2023 (last updated October 08, 2023)
Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user parameter.
Attacker Value
Unknown

CVE-2021-37777

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive information disclosure.
Attacker Value
Unknown

CVE-2021-39486

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.
Attacker Value
Unknown

CVE-2020-20693

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
Attacker Value
Unknown

CVE-2020-20695

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.