CVE-2020-26167: Critical severity thedaylightstudio fuel cms vulnerability
Published Nov 4, 2020
·Updated
In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS<=1.4.12
Event History
Nov 4, 2020
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-26167?
CVE-2020-26167 is a vulnerability in FUEL CMS 11.4.12 and earlier that allows an anonymous user to take complete ownership of any account, including an administrator one.
2
What is the severity of CVE-2020-26167?
CVE-2020-26167 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2020-26167 affect FUEL CMS?
CVE-2020-26167 allows an anonymous user to gain complete ownership of any account in FUEL CMS, including administrator accounts.
4
Which version of FUEL CMS is affected by CVE-2020-26167?
FUEL CMS version 11.4.12 and earlier are affected by CVE-2020-26167.
5
How can I fix CVE-2020-26167?
To fix CVE-2020-26167, you should update FUEL CMS to a version newer than 11.4.12.