MEDIUM6.5
GHSA-rpjw-97p8-p2xp
Gila CMS SQL Injection
Details
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/gilacms/gila
Introduced in:
0No fixed version published yet for gilacms/gila (composer). Pin to a known-safe version or switch to an alternative.