CVE-2020-24791
CRITICALThedaylightstudio Fuel Cms - SQL Injection
Title source: ruleDescription
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploits (1)
References (3)
Scores
CVSS v3
9.8
EPSS
0.0356
EPSS Percentile
87.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
thedaylightstudio/fuel_cms
1.4.8
Published
Mar 10, 2021
Tracked Since
Feb 18, 2026