HIGH8.8
GHSA-hwqc-pgjw-vjqp
Cross-Site Request Forgery in GilaCMS
Details
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/gilacms/gila
Introduced in:
0No fixed version published yet for gilacms/gila (composer). Pin to a known-safe version or switch to an alternative.