CVE-2021-47980

HIGH

Fuel CMS 1.4.13 Blind SQL Injection via col Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47980. PoCs published by Rahad Chowdhury.

AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Fuel CMS 1.4.13 via the 'col' parameter in the activity log feature. The PoC uses time-based SQL injection (sleep function) to confirm the vulnerability.

Description

Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the 'col' parameter to extract database information based on response time delays.

Exploits (1)

exploitdb WORKING POC
by Rahad Chowdhury · textwebappsphp
https://www.exploit-db.com/exploits/50523

This exploit demonstrates a blind SQL injection vulnerability in Fuel CMS 1.4.13 via the 'col' parameter in the activity log feature. The PoC uses time-based SQL injection (sleep function) to confirm the vulnerability.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Fuel CMS 1.4.13
Auth required
Prerequisites: Authenticated access to the Fuel CMS admin panel
devstral-2 · analyzed May 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: Fuel CMS 1.4.13 Blind SQL Injection via col Parameter
https://www.vulncheck.com/advisories/fuel-cms-blind-sql-injection-via-col-parameter
Exploit exploit
ExploitDB-50523
https://www.exploit-db.com/exploits/50523
Product product
Official Product Homepage
https://www.getfuelcms.com/

Scores

CVSS v3 7.1
EPSS 0.0023
EPSS Percentile 13.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Getfuelcms/Fuel CMS 1.4.13
Published May 16, 2026
Tracked Since May 16, 2026