Loading
Generated remediation guidance and an executive summary. No account required.
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.
Use CWE-79, Thedaylightstudio vendor hub and Fuel Cms product page to widen CVE-2019-15228 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-30457, CVE-2020-22153 and CVE-2020-22151 for nearby disclosures in the same product family.