CVE-2020-17463
high-risk
Published 2020-08-13
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Do I need to act?
!
17.5% chance of exploitation in next 30 days
EPSS score — higher than 82% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
+
Fix available
Upgrade to: e59872e6f5c9075919fba96a5ce8829492ad82cc
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (11)
Technical Description
https://cwe.mitre.org/data/definitions/89.html
Vendor Advisory
https://getfuelcms.com
Third Party Advisory
https://github.com/daylightstudio/FUEL-CMS/archive/master.zip
Technical Description
https://cwe.mitre.org/data/definitions/89.html
Vendor Advisory
https://getfuelcms.com
Third Party Advisory
https://github.com/daylightstudio/FUEL-CMS/archive/master.zip
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-...
57
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
20/34 · Moderate
Exposure
5/34 · Minimal