CVE-2021-38727: SQL Injection
Published Sep 9, 2021
·Updated
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.5.0
Event History
Sep 9, 2021
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38727?
CVE-2021-38727 is a SQL Injection vulnerability in FUEL CMS 1.5.0.
2
How severe is CVE-2021-38727?
CVE-2021-38727 has a severity rating of 9.8 (Critical).
3
How does CVE-2021-38727 occur?
CVE-2021-38727 occurs when an attacker uses a specially crafted 'col' parameter in the /fuel/index.php/fuel/logs/items endpoint to inject malicious SQL code.
4
Is FUEL CMS 1.5.0 the only affected version?
Yes, FUEL CMS 1.5.0 is the only affected version of the software.
5
What is the Common Weakness Enumeration (CWE) for CVE-2021-38727?
The Common Weakness Enumeration (CWE) for CVE-2021-38727 is CWE-89 (SQL Injection).