Description
Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the -col- parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the -col- parameter to extract database information based on response time delays.
CVSS 7.1EPSS 0.22599999999999998%Risque 0.72
Voir la source- Publication
- 2026-05-16 16:16:23
- Versions concernées
- ==1.4.13
- Type
- Core software
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N