LOW3.8
GHSA-3pfj-g4wr-qj3j
Gila CMS SQL Injection vulnerability
Details
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/gilacms/gila
Introduced in:
0No fixed version published yet for gilacms/gila (composer). Pin to a known-safe version or switch to an alternative.