First published: Fri Jun 09 2023(Updated: )
Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | =1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33557 is a SQL injection vulnerability found in Fuel CMS v1.5.2.
CVE-2023-33557 has a severity rating of 8.8, which is considered high.
The vulnerability in CVE-2023-33557 allows an attacker to perform SQL injection by exploiting the 'id' parameter in the 'Blocks.php' controller.
Fuel CMS v1.5.2 is the affected software in CVE-2023-33557.
To fix CVE-2023-33557, it is recommended to update to a newer version of Fuel CMS that includes a fix for the SQL injection vulnerability.