Critical severity9.8NVD Advisory· Published Jan 5, 2021· Updated Jun 17, 2026
CVE-2020-26045
CVE-2020-26045
Description
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:thedaylightstudio:fuel_cms:1.4.11:*:*:*:*:*:*:*
- FUEL CMS/FUEL CMSdescription
Patches
Vulnerability mechanics
References
3- github.com/daylightstudio/FUEL-CMS/issues/575nvdExploitThird Party Advisory
- github.com/daylightstudio/FUEL-CMS/releases/tag/1.4.11nvdRelease NotesThird Party Advisory
- getfuelcms.comnvdProduct
News mentions
0No linked articles in our index yet.