First published: Thu Aug 13 2020(Updated: )
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | =1.4.7 | |
TheDayLightStudio Fuel CMS | ||
=1.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17463 is a SQL Injection vulnerability in Fuel CMS 1.4.7.
CVE-2020-17463 allows SQL Injection attacks on the col parameter of /pages/items, /permissions/items, or /navigation/items endpoints in Fuel CMS 1.4.7.
CVE-2020-17463 is considered critical with a severity score of 9.8.
To fix CVE-2020-17463, upgrade Fuel CMS to a version that is not affected, such as 1.4.8 or later.
You can find more information about CVE-2020-17463 on the official Fuel CMS website.