MidnightBSD

Advisories for gilacms

CVE-2019-11456 MEDIUM

Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
gilacms gila_cms 1.10.1
CVE-2019-11515 MEDIUM

core/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
gilacms gila_cms 1.10.1
CVE-2019-9647 MEDIUM

Gila CMS 1.9.1 has XSS.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
gilacms gila_cms 1.9.1