CVE-2021-47980
📛 CVE Title
(no title)
Description
Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the 'col' parameter to extract database information based on response time delays.
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2021-47980 on 2026-07-03. Shown when MITRE's text differs from the cvelistV5 mirror.
Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the 'col' parameter to extract database information based on response time delays.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.1 / 10
- CVSS vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N- Effective score
- 7.1 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2021-47980
- Linked Threat
- CVE-2021-47980 — CVE-2021-47980
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-16 16:16:23 UTC
- NVD last modified
- 2026-05-18 17:26:40 UTC
- NVD CVSS v3.1
- 7.1 / 10 HIGH source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 4.2 / 10
- EPSS score
- 0.0003 (probability of exploitation in next 30 days)
- EPSS percentile
- 8.51% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD-assigned CWE(s):
CWE-89
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-05-25 00:06 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2021-34833 - Assigner
- VulnCheck
- Published
- May 16, 2026, 3:26:19 PM
- Updated
- May 18, 2026, 1:50:17 PM
- EUVD base score (CVSS 4.0)
-
7.1 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0300
- Vendors
- Getfuelcms
- Products
-
Fuel CMS (1.4.13)
- Aliases
-
GHSA-p5g4-2whh-fvpw
ENISA description: Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the 'col' parameter to extract database information based on response time delays.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/daylightstudio/FUEL-CMS/archive/1.4.13.zip tenable:github.com
- https://nvd.nist.gov/vuln/detail/CVE-2021-47980 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2021-47980 tenable:www.cve.org
- https://www.exploit-db.com/exploits/50523 tenable:www.exploit-db.com
- https://www.first.org/epss/ tenable:www.first.org
- https://www.getfuelcms.com/ tenable:www.getfuelcms.com
- https://www.vulncheck.com/advisories/fuel-cms-blind-sql-injection-via-col-parameter tenable:www.vulncheck.com
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/daylightstudio/FUEL-CMS/archive/1.4.13.zip disclosure@vulncheck.com
- https://www.exploit-db.com/exploits/50523 disclosure@vulncheck.com
- https://www.getfuelcms.com/ disclosure@vulncheck.com
- https://www.vulncheck.com/advisories/fuel-cms-blind-sql-injection-via-col-parameter disclosure@vulncheck.com
Remediations (9)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:4sysops.com
Starting in April 2026, Windows updates will change the default Kerberos ticket issuance behavior to AES-SHA1 for accounts without explicit encryption settings, while RC4 can still be used where explicitly enabled. This change, driven by CVE -2026-20833, affects every Windows Server environment where service accounts or devices still rely on RC4. Any service account, NAS device, or legacy ...
2026-05-26 02:55 UTC -
web:feedly.com
Mitigation Recommended mitigations : - Apply Microsoft security updates immediately - Prioritize patching systems with network exposure - Update all Windows systems to the latest security patch versions - Implement network segmentation - Use advanced endpoint protection - Monitor for suspicious network activities - Restrict network access where ...
2026-05-26 02:55 UTC -
web:securityvulnerability.io
What is CVE-2021-47980 ? Fuel CMS version 1.4.13 is susceptible to a blind SQL injection vulnerability that allows authenticated users to craft malicious SQL queries via the 'col' parameter in the Activity Log interface. Attackers can exploit this flaw by sending specially crafted requests to the logs endpoint, enabling them to extract sensitive database information based on the variations in ...
2026-05-26 02:55 UTC -
web:support.microsoft.com
This out-of-band update for Windows 11, version 25H2 and 24H2 (KB5085518) includes fixes and improvements. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of Windows software updates ...
2026-05-26 02:55 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-05-26 02:55 UTC -
web:undercodenews.com
The CVE -2025-47981 saga also underlines the role of automated patch management. Companies that lag in deploying patches—even by a few days—could face system-wide breaches once this vulnerability hits the wild. With ransomware actors increasingly leveraging RCE vulnerabilities, the time between disclosure and exploitation is shrinking rapidly.
2026-05-26 02:55 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-26 02:55 UTC -
web:www.howtogeek.com
In this case, use your PC's built-in Windows Update troubleshooter to automatically find and fix issues with your updates. Only a little interaction is required from your end. To run that tool, go to Settings > Update & Security > Troubleshoot > Additional Troubleshooters > Windows Update and click "Run the Troubleshooter".
2026-05-26 02:55 UTC -
web:www.nist.gov
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.
2026-05-26 02:55 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.