Vendor
An unauthenticated remote code execution vulnerability in Fuel CMS (CVE-2018-16763) allows attackers to inject and execute arbitrary PHP code via the filter parameter, leading to full system compromise.