MEDIUM5.4
GHSA-6675-wwqr-jhmf
Cross-site Scripting in GilaCMS
Details
A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/gilacms/gila
Introduced in:
0No fixed version published yet for gilacms/gila (composer). Pin to a known-safe version or switch to an alternative.