Skip to content
Threat Feed
high advisory

Remote Code Execution in Fuel CMS via CVE-2018-16763

An unauthenticated remote code execution vulnerability in Fuel CMS (CVE-2018-16763) allows attackers to inject and execute arbitrary PHP code via the filter parameter, leading to full system compromise.

CVE search metadata

CVE search record: CVE-2018-16763. Severity: critical. CVSS: 9.8. EPSS: 82.94%. KEV: no. Product: Fuel CMS (<= 1.4.2). Brief: Remote Code Execution in Fuel CMS via CVE-2018-16763. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fuelcms-rce/

Fuel CMS versions 1.4.2 and earlier contain a critical remote code execution (RCE) vulnerability, tracked as CVE-2018-16763. The vulnerability exists due to improper input sanitization in the 'filter' parameter within the '/fuel/pages/select/' endpoint. Unauthenticated attackers can leverage this flaw to perform PHP code injection by crafting specific HTTP requests that utilize 'eval' or other execution primitives. Recent disclosure of functional exploit scripts on platforms such as Sploitus significantly increases the risk of exploitation for any internet-facing instances that remain unpatched. Successful exploitation allows for the deployment of persistent web shells, arbitrary command execution under the context of the web server user, and unauthorized access to sensitive system files.

Attack Chain

  1. Attacker identifies a target server running an outdated version of Fuel CMS (1.4.2 or earlier).
  2. Attacker sends a crafted HTTP GET or POST request to the '/fuel/pages/select/' endpoint.
  3. The request includes a malicious payload injected into the 'filter' query parameter (e.g., using 'file_put_contents' to create a file).
  4. The Fuel CMS application unsafely evaluates the input via an internal 'eval' or similar function, executing the attacker's PHP code.
  5. The execution results in the creation of a persistent PHP web shell file on the web server's filesystem.
  6. Attacker sends follow-up requests to the newly uploaded web shell to execute arbitrary system commands (e.g., 'id', 'ls').
  7. Attacker uses the web shell to exfiltrate sensitive files, such as '/etc/passwd', to their remote machine.

Impact

Successful exploitation of CVE-2018-16763 provides unauthenticated remote code execution. Attackers can gain complete control over the web application and the underlying server, potentially leading to data exfiltration, service disruption, and further lateral movement within the network. Given the ease of exploitation, any exposed Fuel CMS instance is at high risk of automated compromise.

Recommendation

Prioritized, concrete actions for detection engineering and security teams:

  • Immediately upgrade Fuel CMS to a version later than 1.4.2 to address the underlying vulnerability.
  • Implement Web Application Firewall (WAF) rules to inspect incoming HTTP requests for suspicious patterns in the 'filter' parameter of '/fuel/pages/select/', specifically looking for PHP function keywords like 'eval', 'file_put_contents', or common shell metacharacters.
  • Monitor web server logs for HTTP requests containing abnormal URL query strings or payloads targeting the specified endpoint.
  • Review filesystem integrity for unexpected .php files created in the application's root or web-accessible directories, which may indicate the presence of a web shell.
  • Deploy the Sigma rules below to identify and block exploitation attempts.

Immediate actions

Upgrade Fuel CMS to version > 1.4.2

IT Operations 24h

Threat Hunt

Search web logs for requests to /fuel/pages/select/ with suspicious PHP functions in the filter query parameter.

T1190 high high confidence hunt now

Data: Web server access logs

Mitigations

Deploy WAF rules to block requests to /fuel/pages/select/ containing common PHP execution keywords.

immediate SOC

CVE-2018-16763

Detection coverage 1

Detect CVE-2018-16763 Exploitation Attempt

high

Detects exploitation attempts against Fuel CMS by monitoring requests to the vulnerable endpoint with shell-related payloads in the filter parameter.

sigma tactics: execution, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →