CRITICAL
CVE-2020-17463
CVSS
9.8
KEV
Description
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Summary dbcve.org
SQL injection vulnerability in FUEL CMS 1.4.7 allows unauthenticated attackers to inject malicious SQL queries through the 'col' parameter in the /pages/items, /permissions/items, and /navigation/items endpoints. This critical flaw (CVSS 9.8) can lead to complete database compromise including data exfiltration, modification, or deletion.
Mitigation
Upgrade to a patched version of FUEL CMS if available, or implement proper parameterized queries/prepared statements with input validation for the 'col' parameter across all affected endpoints to remediate the SQL injection.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
89.69%
Probability of exploitation in next 30 days
99.8th percentile
References
http://packetstormsecurity.com/files/158840/Fuel-CMS-1.4.7-SQL-Injection.html
Exploit, Third Party Advisory, VDB Entry
https://cwe.mitre.org/data/definitions/89.html
Technical Description
https://getfuelcms.com
Vendor Advisory
https://github.com/daylightstudio/FUEL-CMS/archive/master.zip
Third Party Advisory
https://github.com/daylightstudio/FUEL-CMS/releases/tag/1.4.8
Release Notes, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17463
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.