Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2020-24950

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.
Attacker Value
Unknown

CVE-2020-22153

Disclosure Date: July 03, 2023 (last updated October 08, 2023)
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
Attacker Value
Unknown

CVE-2020-22152

Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function.
Attacker Value
Unknown

CVE-2020-22151

Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
Attacker Value
Unknown

CVE-2021-36570

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.
Attacker Value
Unknown

CVE-2021-36569

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
Attacker Value
Unknown

CVE-2020-24791

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Attacker Value
Unknown

CVE-2020-23722

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.
Attacker Value
Unknown

CVE-2020-28705

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /pages/delete/3.
Attacker Value
Unknown

CVE-2020-23721

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.