First published: Mon Jul 03 2023(Updated: )
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | =1.4.6 | |
=1.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22151 is a permissions vulnerability in Fuel-CMS v.1.4.6 that allows a remote attacker to execute arbitrary code.
The severity of CVE-2020-22151 is critical with a CVSS score of 9.8.
CVE-2020-22151 affects Fuel-CMS version 1.4.6.
An attacker can exploit CVE-2020-22151 by sending a specially crafted zip file to the assets parameter of the upload function.
Yes, a fix is available for CVE-2020-22151. It is recommended to update to a patched version of Fuel-CMS.