{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3athedaylightstudiofuel_cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:thedaylightstudio:fuel_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2018-16763"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fuel CMS (\u003c= 1.4.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Thedaylightstudio"],"content_html":"\u003cp\u003eFuel CMS versions 1.4.2 and earlier contain a critical remote code execution (RCE) vulnerability, tracked as CVE-2018-16763. The vulnerability exists due to improper input sanitization in the 'filter' parameter within the '/fuel/pages/select/' endpoint. Unauthenticated attackers can leverage this flaw to perform PHP code injection by crafting specific HTTP requests that utilize 'eval' or other execution primitives. Recent disclosure of functional exploit scripts on platforms such as Sploitus significantly increases the risk of exploitation for any internet-facing instances that remain unpatched. Successful exploitation allows for the deployment of persistent web shells, arbitrary command execution under the context of the web server user, and unauthorized access to sensitive system files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target server running an outdated version of Fuel CMS (1.4.2 or earlier).\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP GET or POST request to the '/fuel/pages/select/' endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a malicious payload injected into the 'filter' query parameter (e.g., using 'file_put_contents' to create a file).\u003c/li\u003e\n\u003cli\u003eThe Fuel CMS application unsafely evaluates the input via an internal 'eval' or similar function, executing the attacker's PHP code.\u003c/li\u003e\n\u003cli\u003eThe execution results in the creation of a persistent PHP web shell file on the web server's filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker sends follow-up requests to the newly uploaded web shell to execute arbitrary system commands (e.g., 'id', 'ls').\u003c/li\u003e\n\u003cli\u003eAttacker uses the web shell to exfiltrate sensitive files, such as '/etc/passwd', to their remote machine.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2018-16763 provides unauthenticated remote code execution. Attackers can gain complete control over the web application and the underlying server, potentially leading to data exfiltration, service disruption, and further lateral movement within the network. Given the ease of exploitation, any exposed Fuel CMS instance is at high risk of automated compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Fuel CMS to a version later than 1.4.2 to address the underlying vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect incoming HTTP requests for suspicious patterns in the 'filter' parameter of '/fuel/pages/select/', specifically looking for PHP function keywords like 'eval', 'file_put_contents', or common shell metacharacters.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests containing abnormal URL query strings or payloads targeting the specified endpoint.\u003c/li\u003e\n\u003cli\u003eReview filesystem integrity for unexpected .php files created in the application's root or web-accessible directories, which may indicate the presence of a web shell.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to identify and block exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T05:39:17Z","date_published":"2026-10-01T05:39:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fuelcms-rce/","summary":"An unauthenticated remote code execution vulnerability in Fuel CMS (CVE-2018-16763) allows attackers to inject and execute arbitrary PHP code via the filter parameter, leading to full system compromise.","title":"Remote Code Execution in Fuel CMS via CVE-2018-16763","url":"https://feed.craftedsignal.io/briefs/2026-10-fuelcms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:thedaylightstudio:fuel_cms:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}