Fiyo · Fiyo Cms · CVE-2017-11354
**Name of the Vulnerable Software and Affected Versions**
Fiyo CMS version 2.0.7
**Description**
The issue is related to an SQL injection vulnerability. It occurs in the dapur/apps/app article/sys article.php file through the `name` parameter when editing or adding a tag name.
**Recommendations**
For Fiyo CMS version 2.0.7, avoid using the `name` parameter in the affected file until the issue is resolved. As a temporary workaround, consider restricting access to the sys article.php file to minimize the risk of exploitation.