PT-2021-11072 · Fuel Cms · Fuel Cms
C0Mpu7Er
·
Published
2021-03-10
·
Updated
2021-03-12
·
CVE-2020-24791
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
FUEL CMS version 1.4.8
Description:
The issue allows SQL injection via the
fuel replace id parameter in the "pages/replace/1" endpoint. Exploiting this could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.Recommendations:
For FUEL CMS version 1.4.8, consider disabling the
fuel replace id parameter in the "pages/replace/1" endpoint as a temporary workaround until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the fuel replace id parameter until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuel Cms