Descrição
Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the -col- parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the -col- parameter to extract database information based on response time delays.
CVSS 7.1EPSS 0.22599999999999998%Risco 0.72
Ver fonte- Publicação
- 2026-05-16 16:16:23
- Versões afetadas
- ==1.4.13
- Tipo
- Core software
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N