← Vulnerability feed

Vulnerability record · CVE-2020-17463 · published 13 August 2020

CVE-2020-17463: FUEL CMS SQL injection via col parameter

Thedaylightstudio · Fuel Cms

FUEL CMS 1.4.7 fails to sanitize the col parameter on the /pages/items, /permissions/items, and /navigation/items endpoints, allowing SQL injection. Because the flaw is remotely reachable without authentication, it exposes the CMS database to direct manipulation.

9.8 CVSS 3.1 Critical CISA KEV since 10 Dec 2021 EPSS 90% · top 0.2% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote SQL injection with a CVSS score of 9.8, KEV listing, a public exploit, and very high EPSS probability.

What it is

FUEL CMS 1.4.7 fails to sanitize the col parameter on the /pages/items, /permissions/items, and /navigation/items endpoints, allowing SQL injection. Because the flaw is remotely reachable without authentication, it exposes the CMS database to direct manipulation.

Impact

An attacker can read, modify, or delete arbitrary database contents, including CMS user and permission records, and may pivot to further compromise of the host.

Attack surface

Reached over the network through HTTP requests to the affected /items endpoints; the CVSS vector shows no privileges or user interaction required.

Exploitation

CISA added it to KEV in December 2021, an exploit is published on Packet Storm, and EPSS gives roughly 90 percent 30-day exploitation probability; no ransomware use is documented.

What to do

  • Upgrade FUEL CMS to 1.4.8 or later, which the vendor release notes cover.
  • If upgrade is not immediate, restrict access to the /pages/items, /permissions/items, and /navigation/items endpoints to trusted networks or authenticated administrators.
  • Apply input validation or a WAF rule blocking SQL metacharacters in the col parameter.
  • Review database and CMS admin accounts for unauthorized changes or additions.

Detection

  • Inspect web logs for requests to /pages/items, /permissions/items, or /navigation/items containing SQL syntax in the col parameter.
  • Alert on database errors or unusual query patterns originating from the web application.
  • Monitor for unexpected changes to CMS users, permissions, or navigation records.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-17463 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Fuel CMS SQL Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-17463 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-30457Thedaylightstudio dwoo code injection vulnerabilityAn issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.EPSS 0.78%9.8CVE-2020-22151Thedaylightstudio fuel cms unrestricted file upload vulnerabilityPermissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of t…EPSS 1.5%9.8CVE-2020-22153Thedaylightstudio fuel cms unrestricted file upload vulnerabilityFile Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in t…EPSS 1.5%9.8CVE-2021-38727Thedaylightstudio fuel cms sql injection vulnerabilityFUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/itemsEPSS 1.6%9.8CVE-2020-24791Thedaylightstudio fuel cms sql injection vulnerabilityFUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromi…EPSS 2.6%9.8CVE-2020-26045Thedaylightstudio fuel cms sql injection vulnerabilityFUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise t…EPSS 1.8%9.8CVE-2020-26167Thedaylightstudio fuel cms vulnerabilityIn FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrato…EPSS 3.4%9.8CVE-2018-16762Thedaylightstudio fuel cms sql injection vulnerabilityFUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2020-17463), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.