CVE-2020-26045: SQL Injection
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-26045?
CVE-2020-26045 is a vulnerability in FUEL CMS 1.4.11 that allows SQL Injection via the 'name' parameter in /fuel/permissions/create/.
How severe is CVE-2020-26045?
CVE-2020-26045 has a severity rating of critical (9.8).
How does CVE-2020-26045 impact the application?
Exploiting CVE-2020-26045 could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
What software versions are affected by CVE-2020-26045?
FUEL CMS version 1.4.11 is affected by CVE-2020-26045.
How can I fix CVE-2020-26045?
To fix CVE-2020-26045, update to a version of FUEL CMS that is not affected by the vulnerability.