Executive brief
Fuel CMS, a content management system built on the CodeIgniter framework, is vulnerable to a security flaw in its Activity Log interface. An authorized user with access to the system can execute malicious database commands to extract sensitive information. This could lead to the unauthorized disclosure of internal system data, potentially compromising the entire website's database.
Technical details
A blind SQL injection vulnerability exists in Fuel CMS version 1.4.13 and earlier. The flaw is located within the 'col' parameter of the Activity Log interface (accessible via the /fuel/logs/items endpoint). An authenticated attacker can inject malicious SQL payloads into this parameter to perform time-based blind SQL injection. By observing delays in server responses (e.g., using the SLEEP function), an attacker can systematically extract sensitive data from the underlying database. The vulnerability stems from improper neutralization of special elements used in SQL commands within the logging component. While the vendor website shows a newer version (1.5.2) is available, users on 1.4.13 should upgrade to mitigate this risk.
Affected products
- Daylight Studio Fuel CMS <= 1.4.13
Timeline
- 2021-04-11: disclosed: Vulnerability discovered and exploit developed by Rahad Chowdhury
- 2021-11-15: other: Exploit published to Exploit-DB
- 2026-05-16: advisory: CVE published and enriched by VulnCheck/NVD