CVE-2023-33557: SQL Injection
Published Jun 9, 2023
·Updated
Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.5.2
Event History
Jun 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-33557?
CVE-2023-33557 is a SQL injection vulnerability found in Fuel CMS v1.5.2.
2
What is the severity of CVE-2023-33557?
CVE-2023-33557 has a severity rating of 8.8, which is considered high.
3
How does the vulnerability in CVE-2023-33557 work?
The vulnerability in CVE-2023-33557 allows an attacker to perform SQL injection by exploiting the 'id' parameter in the 'Blocks.php' controller.
4
What is the affected software in CVE-2023-33557?
Fuel CMS v1.5.2 is the affected software in CVE-2023-33557.
5
How can CVE-2023-33557 be fixed?
To fix CVE-2023-33557, it is recommended to update to a newer version of Fuel CMS that includes a fix for the SQL injection vulnerability.