Vulnerability record · CVE-2020-17463 · published 13 August 2020
CVE-2020-17463: FUEL CMS SQL injection via col parameter
Thedaylightstudio · Fuel Cms
FUEL CMS 1.4.7 fails to sanitize the col parameter on the /pages/items, /permissions/items, and /navigation/items endpoints, allowing SQL injection. Because the flaw is remotely reachable without authentication, it exposes the CMS database to direct manipulation.
Description
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote SQL injection with a CVSS score of 9.8, KEV listing, a public exploit, and very high EPSS probability.
What it is
FUEL CMS 1.4.7 fails to sanitize the col parameter on the /pages/items, /permissions/items, and /navigation/items endpoints, allowing SQL injection. Because the flaw is remotely reachable without authentication, it exposes the CMS database to direct manipulation.
Impact
An attacker can read, modify, or delete arbitrary database contents, including CMS user and permission records, and may pivot to further compromise of the host.
Attack surface
Reached over the network through HTTP requests to the affected /items endpoints; the CVSS vector shows no privileges or user interaction required.
Exploitation
CISA added it to KEV in December 2021, an exploit is published on Packet Storm, and EPSS gives roughly 90 percent 30-day exploitation probability; no ransomware use is documented.
What to do
- Upgrade FUEL CMS to 1.4.8 or later, which the vendor release notes cover.
- If upgrade is not immediate, restrict access to the /pages/items, /permissions/items, and /navigation/items endpoints to trusted networks or authenticated administrators.
- Apply input validation or a WAF rule blocking SQL metacharacters in the col parameter.
- Review database and CMS admin accounts for unauthorized changes or additions.
Detection
- Inspect web logs for requests to /pages/items, /permissions/items, or /navigation/items containing SQL syntax in the col parameter.
- Alert on database errors or unusual query patterns originating from the web application.
- Monitor for unexpected changes to CMS users, permissions, or navigation records.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-17463 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Fuel CMS SQL Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158840/Fuel-CMS-1.4.7-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://cwe.mitre.org/data/definitions/89.html | Technical Description |
| https://getfuelcms.com | Vendor Advisory |
| https://github.com/daylightstudio/FUEL-CMS/archive/master.zip | Third Party Advisory |
| https://github.com/daylightstudio/FUEL-CMS/releases/tag/1.4.8 | Release NotesThird Party Advisory |
| http://packetstormsecurity.com/files/158840/Fuel-CMS-1.4.7-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://cwe.mitre.org/data/definitions/89.html | Technical Description |
| https://getfuelcms.com | Vendor Advisory |
| https://github.com/daylightstudio/FUEL-CMS/archive/master.zip | Third Party Advisory |
| https://github.com/daylightstudio/FUEL-CMS/releases/tag/1.4.8 | Release NotesThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17463 | US Government Resource |
Track CVE-2020-17463 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17463), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.