CVE-2020-17463

CVE Published 2020-08-13
Related CWE(s) CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Related Vendor(s) thedaylightstudio
Related Product(s) fuel_cms
Exploitation Reported (CISA KEV) 2021-12-10
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References