Описание
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
Ссылки
- ExploitIssue TrackingThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingThird Party AdvisoryVDB Entry
- ExploitIssue TrackingThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.1.8 (включая)
cpe:2.3:a:fiyo:fiyo_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.24232
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
EPSS
Процентиль: 96%
0.24232
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-284