HTML Injection Vulnerability in Daylight Studio Fuel CMS
CVE-2022-27156

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 April 2022

What is CVE-2022-27156?

The Fuel CMS version 1.5.1 developed by Daylight Studio is susceptible to an HTML Injection vulnerability, allowing attackers to inject arbitrary HTML and JavaScript code. This flaw can be exploited to compromise the security of web applications by manipulating content, potentially leading to unauthorized access and data breaches. Developers and users of Fuel CMS should take immediate steps to remediate this threat by applying the necessary patches and updates as outlined in the official documentation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.