LOW3.8
GHSA-4vf6-2rmx-fgqx
Gila CMS SQL Injection vulnerability
Details
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/gilacms/gila
Introduced in:
0No fixed version published yet for gilacms/gila (composer). Pin to a known-safe version or switch to an alternative.