MidnightBSD

Advisories for thedaylightstudio

CVE-2018-16416 MEDIUM

Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
thedaylightstudio fuel_cms 1.4
CVE-2018-16762 HIGH

FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
thedaylightstudio fuel_cms *
CVE-2018-16763 HIGH

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-74,

Products Affected

Vendor Product Version
thedaylightstudio fuel_cms *
CVE-2018-20136 LOW

XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
thedaylightstudio fuel_cms 1.4.3
CVE-2018-20137 LOW

XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
thedaylightstudio fuel_cms 1.4.3
CVE-2018-20188 MEDIUM

FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
thedaylightstudio fuel_cms 1.4.3