Executive brief
FUEL CMS 1.4.7 is vulnerable to SQL injection via the 'col' parameter in the /pages/items, /permissions/items, and /navigation/items endpoints. An unauthenticated remote attacker can exploit this to execute arbitrary SQL commands against the underlying database.
Affected products
- Daylight Studio FUEL CMS 1.4.7
Timeline
- 2020-08-13: disclosed: NVD Published Date
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog