First published: Wed Mar 10 2021(Updated: )
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | =1.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24791 is a SQL injection vulnerability in FUEL CMS 1.4.8.
CVE-2020-24791 is categorized as critical with a severity value of 9.8.
CVE-2020-24791 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1, which can lead to application compromise, unauthorized data access or modification, and exploitation of latent vulnerabilities in the database.
To fix CVE-2020-24791 in FUEL CMS 1.4.8, it is recommended to update to a patched version provided by TheDayLightStudio or apply the necessary security patches.
More information about CVE-2020-24791 can be found at the following references: [link1], [link2], [link3].