Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown

CVE-2020-23721

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.
Attacker Value
Unknown

CVE-2020-26045

Disclosure Date: January 05, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Attacker Value
Unknown

CVE-2020-26046

Disclosure Date: January 05, 2021 (last updated February 22, 2025)
FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.
Attacker Value
Unknown

CVE-2020-26167

Disclosure Date: November 04, 2020 (last updated November 28, 2024)
In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.
Attacker Value
Unknown

CVE-2020-17463

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Attacker Value
Unknown

CVE-2019-15228

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.
0
Attacker Value
Unknown

CVE-2019-15229

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
0
Attacker Value
Unknown

CVE-2018-20188

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
0
Attacker Value
Unknown

CVE-2018-20136

Disclosure Date: December 13, 2018 (last updated November 27, 2024)
XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
0
Attacker Value
Unknown

CVE-2018-20137

Disclosure Date: December 13, 2018 (last updated November 27, 2024)
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.
0