vendor:
Gila CMS
by:
Omer Shaik (unknown_exploit)
7.5
CVSS
HIGH
Remote Code Execution
79
CWE
Product Name: Gila CMS
Affected Version From: Gila CMS 1.10.9
Affected Version To: Gila CMS 1.10.9
Patch Exists: NO
Related CWE:
CPE: a:gilacms:gila:1.10.9
Platforms Tested: Linux
2023
Gila CMS 1.10.9 – Remote Code Execution (RCE) (Authenticated)
The Gila CMS version 1.10.9 is vulnerable to remote code execution. An attacker with authenticated access can execute arbitrary code on the target system. This can lead to a complete compromise of the system.
Mitigation:
Update to the latest version of Gila CMS to fix the vulnerability. Limit access to trusted users only.