Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2020-24950
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.
0
Attacker Value
Unknown
CVE-2020-22153
Disclosure Date: July 03, 2023 (last updated October 08, 2023)
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
0
Attacker Value
Unknown
CVE-2020-22152
Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function.
0
Attacker Value
Unknown
CVE-2020-22151
Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
0
Attacker Value
Unknown
CVE-2021-36570
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.
0
Attacker Value
Unknown
CVE-2021-36569
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
0
Attacker Value
Unknown
CVE-2020-24791
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
0
Attacker Value
Unknown
CVE-2020-23722
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.
0
Attacker Value
Unknown
CVE-2020-28705
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /pages/delete/3.
0
Attacker Value
Unknown
CVE-2020-23721
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.
0