VendorsThe Daylight Studiofuel_cms1.4.3
Vulnerabilities

The Daylight Studio FUEL CMS 1.4.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-20188
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
Published 2018-12-17 · Modified
8.8EPSS 0.005
CVE-2018-20136
XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
Published 2018-12-13 · Modified
4.8EPSS 0.006
CVE-2018-20137
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.
Published 2018-12-13 · Modified
4.8EPSS 0.006