CISA Known Exploited Vulnerability

CVE-2020-17463

Fuel CMS · Fuel CMS

Fuel CMS SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Unknown

CISA description

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

Required action

Apply updates per vendor instructions.