Skip to content
COOEY

EXPOSURES › CVE-2020-17463

CVE-2020-17463

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-17463 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Fuel CMS 1.4.7 suffers from SQL injection via the col parameter, allowing attackers to extract or manipulate database contents.

This SQL injection flaw in Fuel CMS 1.4.7 enables attackers to read, modify, or delete sensitive data stored in the database. DIB organizations must ensure their CMS platforms are patched and monitored for known vulnerabilities, as unpatched flaws like this are frequently exploited in the wild and can lead to data breaches or compliance violations under NIST 800-171.

Shame score — A known SQL injection vulnerability in an actively exploited CVE (KEV) indicates negligent patching and exposes sensitive data to theft or manipulation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.