CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- September 09, 2018
- Published Date
- September 09, 2018
- Last Updated
- August 05, 2024
- Vendor
- FUEL CMS
- Product
- FUEL CMS
- Description
- FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
- Tags
- Score
- 93.94% (Percentile: 99.87%) as of 2025-06-10
- Exploited in the Wild
- Yes (2025-05-13 00:00:00 UTC) Source
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Score
Exploit Status
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
The Shadowserver (via CIRCL) | 2025-05-13 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16763.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-
Type: github • Created: 2025-04-13 00:45:30 UTC • Stars: 0
altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE
Type: github • Created: 2025-01-08 01:30:07 UTC • Stars: 0
VitoBonetti/CVE-2018-16763
Type: github • Created: 2023-07-16 20:40:45 UTC • Stars: 0
not1cyyy/CVE-2018-16763
Type: github • Created: 2023-01-03 20:47:08 UTC • Stars: 2
p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE
Type: github • Created: 2022-05-31 15:31:37 UTC • Stars: 13
n3rdh4x0r/CVE-2018-16763
Type: github • Created: 2022-01-08 07:15:24 UTC • Stars: 2
wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-16763
Type: github • Created: 2021-11-22 14:53:42 UTC • Stars: 0
padsalatushal/CVE-2018-16763
Type: github • Created: 2021-11-03 04:38:54 UTC • Stars: 5
kxisxr/Bash-Script-CVE-2018-16763
Type: github • Created: 2021-09-27 05:15:38 UTC • Stars: 2
n3m1sys/CVE-2018-16763-Exploit-Python3
Type: github • Created: 2020-10-10 20:23:59 UTC • Stars: 3
hikarihacks/CVE-2018-16763-exploit
Type: github • Created: 2020-09-03 15:06:22 UTC • Stars: 2
dinhbaouit/CVE-2018-16763
Type: github • Created: 2020-03-26 09:38:16 UTC • Stars: 1
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nuclei
-
Added to KEVIntel