6.8
CVSSv2

CVE-2019-20804

Published: 21/05/2020 Updated: 06/10/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 608
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Gila CMS prior to 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gilacms gila cms

Exploits

GilaCMS version 1115 suffers from cross site request forgery and cross site scripting vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> GilaCMS - CVE-2019-13364 CVE-2019-13363 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Rodolfo Augusto d ...