Daylight Studio FuelCMS Path Traversal Vulnerability in Blocks Module

Vulnerability

A path traversal vulnerability has been identified in the Blocks module of Daylight Studio FuelCMS version 1.5.2. This vulnerability allows authenticated users to read specific PHP files on the server, such as database or configuration files, by exploiting improper sanitization of file names in the Blocks module.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files, including database credentials and FuelCMS configuration information. According to the vulnerability report, if an attacker retrieves valid database credentials, they could access all website information, manipulate admin accounts, and disrupt FuelCMS availability by modifying or deleting critical database components.

Reproduction

To reproduce this vulnerability, an authenticated user must have a role that permits 'POST' requests to the '/fuel/blocks/edit/' endpoint. The user can then upload a new block through the 'Blocks' feature, inserting a crafted file name that exploits the path traversal vulnerability. After uploading, the application will prompt to 'import' the file's content, which, if successful, will return the file's contents via the application's response.

Added: Apr 27, 2026, 5:27 PM
Updated: Apr 27, 2026, 5:27 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
6.8
remediation
0.0
relevance
6.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.