Vulnerabilities (CVE)

Filtered by vendor Fiyo Subscribe
Filtered by product Fiyo Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-6823 1 Fiyo 1 Fiyo Cms 2019-10-03 6.5 MEDIUM 8.8 HIGH
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.
CVE-2017-17103 1 Fiyo 1 Fiyo Cms 2017-12-15 6.5 MEDIUM 8.8 HIGH
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
CVE-2017-17104 1 Fiyo 1 Fiyo Cms 2017-12-15 7.8 HIGH 7.5 HIGH
Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].
CVE-2017-17102 1 Fiyo 1 Fiyo Cms 2017-12-14 5.0 MEDIUM 7.5 HIGH
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
CVE-2014-9147 1 Fiyo 1 Fiyo Cms 2017-10-25 5.0 MEDIUM 7.5 HIGH
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.
CVE-2017-11630 1 Fiyo 1 Fiyo Cms 2017-07-31 5.0 MEDIUM 7.5 HIGH
dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853.
CVE-2017-8853 1 Fiyo 1 Fiyo Cms 2017-05-17 6.4 MEDIUM 7.5 HIGH
Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file parameter during an act=db action.