### [CVE-2021-39486](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39486) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser. ### POC #### Reference - https://www.navidkagalwalla.com/gila-cms-vulnerabilities #### Github No PoCs found on GitHub currently.