VDB
Sign up
LOW3.8

GHSA-3pfj-g4wr-qj3j

Gila CMS SQL Injection vulnerability

Details

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/gilacms/gila
Introduced in: 0

No fixed version published yet for gilacms/gila (composer). Pin to a known-safe version or switch to an alternative.

References