CVE-2020-17463: Fuel CMS SQL Injection Vulnerability
Published Aug 13, 2020
·Updated
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Affected Software
2 affected components
TheDayLightStudio Fuel CMS=1.4.7
Fuel CMS Fuel CMS
Event History
Aug 13, 2020
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 10, 2021
Known Exploited
via CISA·12:00 AM
Frequently Asked Questions
1
What is CVE-2020-17463?
CVE-2020-17463 is a SQL Injection vulnerability in Fuel CMS 1.4.7.
2
How does CVE-2020-17463 impact Fuel CMS?
CVE-2020-17463 allows SQL Injection attacks on the col parameter of /pages/items, /permissions/items, or /navigation/items endpoints in Fuel CMS 1.4.7.
3
What is the severity of CVE-2020-17463?
CVE-2020-17463 is considered critical with a severity score of 9.8.
4
How can I fix CVE-2020-17463?
To fix CVE-2020-17463, upgrade Fuel CMS to a version that is not affected, such as 1.4.8 or later.
5
Where can I find more information about CVE-2020-17463?
You can find more information about CVE-2020-17463 on the official Fuel CMS website.