CVE-2018-16763

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote...

Basic Information

CVE State
PUBLISHED
Reserved Date
September 09, 2018
Published Date
September 09, 2018
Last Updated
August 05, 2024
Vendor
FUEL CMS
Product
FUEL CMS
Description
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
Tags
php nuclei_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score

Score
93.94% (Percentile: 99.87%) as of 2025-06-10

Exploit Status

Exploited in the Wild
Yes (2025-05-13 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-05-13 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-

Type: github • Created: 2025-04-13 00:45:30 UTC • Stars: 0

The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.

altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE

Type: github • Created: 2025-01-08 01:30:07 UTC • Stars: 0

Fuel CMS 1.4.1 - Remote Code Execution

VitoBonetti/CVE-2018-16763

Type: github • Created: 2023-07-16 20:40:45 UTC • Stars: 0

Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x

not1cyyy/CVE-2018-16763

Type: github • Created: 2023-01-03 20:47:08 UTC • Stars: 2

CVE-2018-16763 FuelCMS 1.4 Remote Code Execution, this version of FuelCMS is still vulnerable until now

p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE

Type: github • Created: 2022-05-31 15:31:37 UTC • Stars: 13

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

n3rdh4x0r/CVE-2018-16763

Type: github • Created: 2022-01-08 07:15:24 UTC • Stars: 2

wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-16763

Type: github • Created: 2021-11-22 14:53:42 UTC • Stars: 0

A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.

padsalatushal/CVE-2018-16763

Type: github • Created: 2021-11-03 04:38:54 UTC • Stars: 5

Fuel CMS 1.4.1 - Remote Code Execution

kxisxr/Bash-Script-CVE-2018-16763

Type: github • Created: 2021-09-27 05:15:38 UTC • Stars: 2

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

n3m1sys/CVE-2018-16763-Exploit-Python3

Type: github • Created: 2020-10-10 20:23:59 UTC • Stars: 3

hikarihacks/CVE-2018-16763-exploit

Type: github • Created: 2020-09-03 15:06:22 UTC • Stars: 2

This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1

dinhbaouit/CVE-2018-16763

Type: github • Created: 2020-03-26 09:38:16 UTC • Stars: 1

CVE 2018-16763

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel