Executive brief
Daylight Studio FuelCMS, a content management system used for building websites, contains a security flaw in its login and password reset component. An attacker could exploit this vulnerability to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive information or the modification of website content. This could result in a full compromise of the website's data and administrative controls.
Technical details
A SQL injection vulnerability exists in Daylight Studio FuelCMS v1.5.2 within the Login controller (/controllers/Login.php). The flaw is specifically located in the password reset functionality, where user-supplied input is improperly neutralized before being used in a SQL command (CWE-89). An unauthenticated remote attacker can exploit this by sending specially crafted requests to the login component. Successful exploitation allows the attacker to execute arbitrary SQL queries, potentially leading to unauthorized data retrieval, modification, or administrative bypass. While the attack vector is network-based and requires no privileges, the CVSS assessment indicates high complexity, likely due to specific environmental or input requirements for successful injection.
Affected products
- Daylight Studio FuelCMS 1.5.2
Timeline
- 2026-03-26: advisory: Initial NVD publication date
- 2026-07-04: other: Last modified date in NVD record