PT-2017-11994 · Fiyo · Fiyo Cms
Melody
+1
·
Published
2017-07-18
·
Updated
2017-07-20
·
CVE-2017-11412
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fiyo CMS version 2.0.7
Description
The issue concerns SQL injection. It can be exploited via the
$ GET['id'] variable in the dapur/apps/app comment/controller/comment status.php file.Recommendations
For Fiyo CMS version 2.0.7, consider restricting access to the comment status.php file until a patch is available. As a temporary workaround, avoid using the
id variable in the affected API endpoint until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fiyo Cms