Account Ownership Vulnerability in FUEL CMS by Daylight Studio
CVE-2020-26167
9.8CRITICAL
What is CVE-2020-26167?
In FUEL CMS version 11.4.12 and earlier, a security flaw in the page preview feature permits an unauthorized user to gain complete control over any account, including those with administrative privileges. This vulnerability highlights a significant risk, allowing malicious actors to exploit the system by impersonating legitimate users and potentially compromising sensitive data.
