CVE-2020-26045

CRITICAL

Thedaylightstudio Fuel Cms - SQL Injection

Title source: rule
STIX 2.1

Description

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Scores

CVSS v3 9.8
EPSS 0.0074
EPSS Percentile 73.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
thedaylightstudio/fuel_cms 1.4.11
Published Jan 05, 2021
Tracked Since Feb 18, 2026