GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20692
Reference (s):
- http://test.lingdong.store/2019/10/13/SQL-injection-in-Gila-CMS-version-1-11-4/
- https://github.com/GilaCMS/gila/issues/50

