CVE-2021-37777
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive information disclosure.
- Affected products
- Gila Cms
- Gilacms Gila Cms
- = 2.2.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.7% (76th percentile)
- Weakness
- CWE-639
- NVD status
- Modified
- Published
- 2021-10-04
CVE-2021-37777 at NVD
No indexed exploits for CVE-2021-37777 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-37777 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.