Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown
CVE-2020-23721
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.
0
Attacker Value
Unknown
CVE-2020-26045
Disclosure Date: January 05, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
0
Attacker Value
Unknown
CVE-2020-26046
Disclosure Date: January 05, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.
0
Attacker Value
Unknown
CVE-2020-26167
Disclosure Date: November 04, 2020 (last updated November 28, 2024)
In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.
0
Attacker Value
Unknown
CVE-2020-17463
Disclosure Date: August 13, 2020 (last updated February 21, 2025)
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
0
Attacker Value
Unknown
CVE-2019-15228
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.
0
Attacker Value
Unknown
CVE-2019-15229
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
0
Attacker Value
Unknown
CVE-2018-20188
Disclosure Date: December 17, 2018 (last updated November 27, 2024)
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
0
Attacker Value
Unknown
CVE-2018-20136
Disclosure Date: December 13, 2018 (last updated November 27, 2024)
XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
0
Attacker Value
Unknown
CVE-2018-20137
Disclosure Date: December 13, 2018 (last updated November 27, 2024)
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.
0