GHSA-7rvp-xqj7-rxf2
Dashboard / Vulnerabilities / GHSA-7rvp-xqj7-rxf2
Summary: Withdrawn Advisory: Daylight Studio FUEL-CMS SQLi Vulnerability
Details: ## Withdrawn Advisory This advisory has been withdrawn because this vulnerability does not affect a package in a [supported ecosystem](https://docs.github.com/en/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database#about-types-of-security-advisories). This link has been maintained to preserve external references. ## Original Description SQL Injection vulnerability in file `Base_module_model.php` in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the `col` parameter to function `list_items`.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-24950, https://github.com/daylightstudio/FUEL-CMS/issues/562, https://github.com/daylightstudio/FUEL-CMS/commit/c8d9381d39b1c0f5488cf059ea9aa659ee227da4, https://github.com/daylightstudio/FUEL-CMS
Affected packages
Package
Name: codeigniter/framework
Purl: pkg:composer/codeigniter/framework
Affected ranges
Type: ECOSYSTEM
Events:
