← Πίσω στην αναζήτηση CVE

CVE-2021-47980

Fuel CMS

Περιγραφή

Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the -col- parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the -col- parameter to extract database information based on response time delays.

CVSS 7.1EPSS 0.22599999999999998%Κίνδυνος 0.72
Προβολή πηγής
Δημοσίευση
2026-05-16 16:16:23
Επηρεαζόμενες εκδόσεις
==1.4.13
Τύπος
Core software
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N