VendorsThe Daylight Studiofuel_cms1.4.6
Vulnerabilities

The Daylight Studio FUEL CMS 1.4.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-22151
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
Published 2023-07-03 · Modified
9.8EPSS 0.015
CVE-2020-22153
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
Published 2023-07-03 · Modified
9.8EPSS 0.015
CVE-2020-22152
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function.
Published 2023-07-03 · Modified
5.4EPSS 0.006