CVE-2020-26623
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
- Affected products
- Gila Cms
- Gilacms Gila Cms
- ≤ 1.15.4
- Fix
- Available
- CVSS 3.1
- 3.8 LOW
- EPSS
- 0.7% (50th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2024-01-02
CVE-2020-26623 at NVD
2 known exploits for CVE-2020-26623
Proof-of-concept code and exploit modules indexed by Sploitus