CVE-2020-24791
CRITICALFUEL CMS 1.4.8 - SQL Injection via fuel_replace_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-24791. PoCs published by c0mpu7er.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in Fuel CMS 1.4.8 via the 'fuel_replace_id' parameter. The PoC includes a Burp Suite request and SQLmap usage to extract database information.
Description
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in Fuel CMS 1.4.8 via the 'fuel_replace_id' parameter. The PoC includes a Burp Suite request and SQLmap usage to extract database information.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H