Loading
Generated remediation guidance and an executive summary. No account required.
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.
Use CWE-74, Thedaylightstudio vendor hub and Fuel Cms product page to widen CVE-2021-38290 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-30457, CVE-2020-22153 and CVE-2020-22151 for nearby disclosures in the same product family.