Thedaylightstudio

Fuel Cms

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.26%
  • Veröffentlicht 10.03.2021 14:15:12
  • Zuletzt bearbeitet 21.11.2024 05:14:02

An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 10.03.2021 14:15:12
  • Zuletzt bearbeitet 21.11.2024 05:14:02

An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 05.01.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:19:05

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 05.01.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:19:05

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

  • EPSS 2.95%
  • Veröffentlicht 04.11.2020 17:15:13
  • Zuletzt bearbeitet 30.05.2025 16:15:25

In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.

Warnung Exploit
  • EPSS 15.27%
  • Veröffentlicht 13.08.2020 13:15:17
  • Zuletzt bearbeitet 07.11.2025 22:02:23

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 20.08.2019 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:28:15

FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 20.08.2019 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:28:14

FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 17.12.2018 19:29:04
  • Zuletzt bearbeitet 21.11.2024 04:01:03

FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 13.12.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:55

XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.