CVE-2020-20693 describes a Cross-Site Request Forgery (CSRF) vulnerability in GilaCMS v1.11.4 that allows an authenticated attacker to create new administrator accounts. This high-severity flaw (CVSS 8.8) has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability if successfully exploited. Despite its significant impact, there is currently no public exploit code available, nor is there evidence of active exploitation or notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.11.4CPE matchmatch criteria | cpe:2.3:a:gilacms:gila_cms:1.11.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.