Daylight Studio FuelCMS
cpe:2.3:a:daylightstudio:fuel_cms:*:*:*:*:*:*:*, +1 more
- 1.5.2
A remote code execution vulnerability has been identified in Daylight Studio FuelCMS version 1.5.2, specifically within the Blocks module. This vulnerability arises from improper authorization, allowing authenticated users to execute arbitrary code.
Exploitation of this vulnerability allows authenticated users to execute arbitrary code on the server where FuelCMS is hosted.
To reproduce this vulnerability, log into a FuelCMS application as any user with valid credentials. Once logged in, access the Blocks module through the preview endpoint. Due to the lack of proper authorization enforcement, any authenticated user can invoke this endpoint, which will result in remote code execution on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.