CVE-2018-16763

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
09/09/2018
Last modified:
30/11/2021

Description

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thedaylightstudio:fuel_cms:*:*:*:*:*:*:*:* 1.4.2 (including)