VulnerabilityModified
CVE-2014-9148
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
CRITICAL 9.8EPSS 11.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.45% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- fiyo/fiyo cms
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/131165/FiyoCMS-2.0.1.8-XSS-SQL-Injection-URL-Bypass.htmlExploit, Issue Tracking, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/73437Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/36581/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/131165/FiyoCMS-2.0.1.8-XSS-SQL-Injection-URL-Bypass.htmlExploit, Issue Tracking, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/73437Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/36581/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.