github.com
https://github.com/daylightstudio/FUEL-CMS/issues/561 CVE-2020-24791
CRITICAL
Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
Record summary
CVE-2020-24791 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)ExploitDB exploitby c0mpu7erNot analyzed1 file
References
4github.com
https://github.com/leerina/vulnerability/blob/master/Fuel%20CMS%201.4.8%20SQLi%20vulnerability.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24791 exploit-db.com
https://www.exploit-db.com/exploits/48778