CVE-2020-26046

MEDIUM

Thedaylightstudio Fuel Cms - XSS

Title source: rule
STIX 2.1

Description

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

Scores

CVSS v3 5.4
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
thedaylightstudio/fuel_cms 1.4.11
Published Jan 05, 2021
Tracked Since Feb 18, 2026