CVE-2020-17463 — Fuel CMS SQL Injection Vulnerability
2021-12-10 • CISA Known Exploited Vulnerability
[event] FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Fuel CMS |
| Product | Fuel CMS |
| CWE | CWE-89 |
| CVE ID | CVE-2020-17463 |
| Date Added | 2021-12-10 |
| Due Date | 2022-06-10 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-06-10