Junglewise Threat Intelligence

CVE-2020-17463: Fuel CMS SQL Injection Vulnerability

CVE-2020-17463 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-12-10

Technologies: Daylight Studio FuelCMS. Vendors: Daylight Studio.

Executive brief

FUEL CMS 1.4.7 is vulnerable to SQL injection via the 'col' parameter in the /pages/items, /permissions/items, and /navigation/items endpoints. An unauthenticated remote attacker can exploit this to execute arbitrary SQL commands against the underlying database.

Affected products

  • Daylight Studio FUEL CMS 1.4.7

Timeline

  • 2020-08-13: disclosed: NVD Published Date
  • 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog