-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
While exact code isn't available, the vulnerability pattern suggests: 1) Admin widget handlers receive the 'Area' parameter 2) SQL injection occurs in admin context 3) Typical PHP CMS patterns show controllers passing parameters directly to models 4) The CWE-89 classification indicates direct SQL command injection. The medium confidence comes from matching vulnerability patterns to common MVC implementation practices in PHP CMS systems, though without direct code evidence.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| gilacms/gila | composer | <= 1.15.4 |
KEV Misses 88% of Exploited CVEs- Get the report