FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
{ "versions": [ { "introduced": "0" }, { "last_affected": "1.4.11" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-26045.json"