CVE-2021-38290

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
09/08/2021
Last modified:
17/08/2021

Description

A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thedaylightstudio:fuel_cms:*:*:*:*:*:*:*:* 1.5.0 (including)