QID 376471
Date Published: 2022-03-16
QID 376471: Fuel CMS SQL Injection Vulnerability
Fuel CMS 1.4.7 allows SQL Injection via parameter 'col' in pages/items, permissions/items, navigation/items and logs/items
Affected Version
Fuel CMS 1.4.7
QID Detection Logic(Authenticated)
The QID checks for the vulnerable version from the fuel_constants.php using locate command
Successfully exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Solution
Customers are advised to refer the mentioned site for recent updates Fuel CMS .
Vendor References
CVEs related to QID 376471
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-17463 |
|