CVE-2021-38725: Medium severity TheDayLightStudio Fuel CMS vulnerability
Published Sep 9, 2021
·Updated
Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.5.0
Remediation
Event History
Sep 9, 2021
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38725?
CVE-2021-38725 is a brute force vulnerability found in Fuel CMS 1.5.0 in the Login.php file.
2
What software version is affected by CVE-2021-38725?
Fuel CMS 1.5.0 is affected by CVE-2021-38725.
3
How severe is CVE-2021-38725?
CVE-2021-38725 has a severity rating of 5.3 (medium).
4
How can I fix CVE-2021-38725?
To fix CVE-2021-38725, update Fuel CMS to a version that includes the fix, such as the commit 15934fdd309408640d1f2be18f93a8beadaa5e9b.
5
Where can I find more information about CVE-2021-38725?
More information about CVE-2021-38725 can be found at the following references: [GitHub commit](https://github.com/daylightstudio/FUEL-CMS/commit/15934fdd309408640d1f2be18f93a8beadaa5e9b) and [GitHub issue](https://github.com/daylightstudio/FUEL-CMS/issues/581).