<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Thedaylightstudio - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/thedaylightstudio/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 05:39:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/thedaylightstudio/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Fuel CMS via CVE-2018-16763</title><link>https://feed.craftedsignal.io/briefs/2026-10-fuelcms-rce/</link><pubDate>Thu, 01 Oct 2026 05:39:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fuelcms-rce/</guid><description>An unauthenticated remote code execution vulnerability in Fuel CMS (CVE-2018-16763) allows attackers to inject and execute arbitrary PHP code via the filter parameter, leading to full system compromise.</description><content:encoded><![CDATA[<p>Fuel CMS versions 1.4.2 and earlier contain a critical remote code execution (RCE) vulnerability, tracked as CVE-2018-16763. The vulnerability exists due to improper input sanitization in the 'filter' parameter within the '/fuel/pages/select/' endpoint. Unauthenticated attackers can leverage this flaw to perform PHP code injection by crafting specific HTTP requests that utilize 'eval' or other execution primitives. Recent disclosure of functional exploit scripts on platforms such as Sploitus significantly increases the risk of exploitation for any internet-facing instances that remain unpatched. Successful exploitation allows for the deployment of persistent web shells, arbitrary command execution under the context of the web server user, and unauthorized access to sensitive system files.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target server running an outdated version of Fuel CMS (1.4.2 or earlier).</li>
<li>Attacker sends a crafted HTTP GET or POST request to the '/fuel/pages/select/' endpoint.</li>
<li>The request includes a malicious payload injected into the 'filter' query parameter (e.g., using 'file_put_contents' to create a file).</li>
<li>The Fuel CMS application unsafely evaluates the input via an internal 'eval' or similar function, executing the attacker's PHP code.</li>
<li>The execution results in the creation of a persistent PHP web shell file on the web server's filesystem.</li>
<li>Attacker sends follow-up requests to the newly uploaded web shell to execute arbitrary system commands (e.g., 'id', 'ls').</li>
<li>Attacker uses the web shell to exfiltrate sensitive files, such as '/etc/passwd', to their remote machine.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2018-16763 provides unauthenticated remote code execution. Attackers can gain complete control over the web application and the underlying server, potentially leading to data exfiltration, service disruption, and further lateral movement within the network. Given the ease of exploitation, any exposed Fuel CMS instance is at high risk of automated compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering and security teams:</p>
<ul>
<li>Immediately upgrade Fuel CMS to a version later than 1.4.2 to address the underlying vulnerability.</li>
<li>Implement Web Application Firewall (WAF) rules to inspect incoming HTTP requests for suspicious patterns in the 'filter' parameter of '/fuel/pages/select/', specifically looking for PHP function keywords like 'eval', 'file_put_contents', or common shell metacharacters.</li>
<li>Monitor web server logs for HTTP requests containing abnormal URL query strings or payloads targeting the specified endpoint.</li>
<li>Review filesystem integrity for unexpected .php files created in the application's root or web-accessible directories, which may indicate the presence of a web shell.</li>
<li>Deploy the Sigma rules below to identify and block exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>