vendor:
Fuel CMS
by:
Rahad Chowdhury
8.8
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Fuel CMS
Affected Version From: 1.4.13
Affected Version To: 1.4.13
Patch Exists: YES
Related CWE:
CPE: a:getfuelcms:fuel_cms:1.4.13
Platforms Tested: Kali Linux, PHP 7.4.16, Apache 2.4.46
2021
Fuel CMS 1.4.13 – ‘col’ Blind SQL Injection (Authenticated)
Fuel CMS 1.4.13 is vulnerable to Blind SQL Injection in the 'col' parameter. An attacker can inject malicious SQL queries in the 'col' parameter and can gain access to the database. The exploit can be reproduced by logging into the panel, going to the 'Activity Log' menu, selecting any type option and then injecting a Blind SQL Injection query in the 'col' parameter.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update the application to the latest version.