SQL Injection Vulnerability in FUEL CMS by Daylight Studio
CVE-2021-38723
8.8HIGH
What is CVE-2021-38723?
FUEL CMS version 1.5.0 is susceptible to SQL Injection attacks through the 'col' parameter in the /fuel/index.php/fuel/pages/items endpoint. This vulnerability may allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access to sensitive data or the manipulation of the database. Users are advised to apply any available patches and closely monitor their systems for unusual activity.
