CVE-2019-20804

Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:gilacms:gila_cms:*:*:*:*:*:*:*:*

Information

Published : 2020-05-21 15:15

Updated : 2022-10-06 13:53


NVD link : CVE-2019-20804

Mitre link : CVE-2019-20804


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

gilacms

  • gila_cms