KEVIntel
9.8
CVSS
Critical

CVE-2018-16763

PUBLISHED

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote...

PoC available Remote Low complexity No user interaction
Vendor
Daylight Studio
Product
FUEL CMS
Published
Sep 09, 2018
EPSS

Description

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Proof of concept available

Recorded 2022-05-31 15:31:37 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Jun 06, 2025

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-

github · Created 2025-04-13 00:45:30 UTC · 0 stars

The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.

altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE

github · Created 2025-01-08 01:30:07 UTC · 0 stars

Fuel CMS 1.4.1 - Remote Code Execution

VitoBonetti/CVE-2018-16763

github · Created 2023-07-16 20:40:45 UTC · 0 stars

Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x

antisecc/CVE-2018-16763

github · Created 2023-06-09 13:01:48 UTC · 0 stars

not1cyyy/CVE-2018-16763

github · Created 2023-01-03 20:47:08 UTC · 2 stars

CVE-2018-16763 FuelCMS 1.4 Remote Code Execution, this version of FuelCMS is still vulnerable until now

p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE

github · Created 2022-05-31 15:31:37 UTC · 13 stars

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

n3rdh4x0r/CVE-2018-16763

github · Created 2022-01-08 07:15:24 UTC · 2 stars

wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-16763

github · Created 2021-11-22 14:53:42 UTC · 0 stars

A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.

padsalatushal/CVE-2018-16763

github · Created 2021-11-03 04:38:54 UTC · 5 stars

Fuel CMS 1.4.1 - Remote Code Execution

kxisxr/Bash-Script-CVE-2018-16763

github · Created 2021-09-27 05:15:38 UTC · 2 stars

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

n3m1sys/CVE-2018-16763-Exploit-Python3

github · Created 2020-10-10 20:23:59 UTC · 3 stars

hikarihacks/CVE-2018-16763-exploit

github · Created 2020-09-03 15:06:22 UTC · 2 stars

This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1

dinhbaouit/CVE-2018-16763

github · Created 2020-03-26 09:38:16 UTC · 1 stars

CVE 2018-16763

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Added to KEVIntel