Fiyo · Fiyo Cms · CVE-2017-11631
**Name of the Vulnerable Software and Affected Versions**
Fiyo CMS version 2.0.7
**Description**
The issue is related to SQL injection via the `id` parameter in the dapur/app/app user/controller/status.php file.
**Recommendations**
For Fiyo CMS version 2.0.7, avoid using the `id` parameter in the vulnerable file until the issue is resolved. Consider restricting access to the status.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.