CVE-2018-16762: SQL Injection
Published Sep 9, 2018
·Updated
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or searchterm parameter to pages/items.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS<=1.4.2
Remediation
Patch Available
Event History
Sep 9, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16762?
CVE-2018-16762 is a vulnerability in FUEL CMS 1.4.1 that allows SQL Injection via the layout, published, or search_term parameter to pages/items.
2
What is the severity of CVE-2018-16762?
The severity of CVE-2018-16762 is critical with a CVSS score of 9.8.
3
How does CVE-2018-16762 affect FUEL CMS?
CVE-2018-16762 affects FUEL CMS 1.4.1.
4
How can I fix CVE-2018-16762?
To fix CVE-2018-16762, update FUEL CMS to version 1.4.2 or higher.
5
Where can I find more information about CVE-2018-16762?
More information about CVE-2018-16762 can be found at the following link: https://github.com/daylightstudio/FUEL-CMS/issues/478