Vulnerability Description
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fiyo | Fiyo Cms | 2.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97571Third Party AdvisoryVDB Entry
- https://github.com/Xyntax/POC-T/blob/2.0/script/fiyo2.0.7-getshell.pyExploitThird Party Advisory
- http://www.securityfocus.com/bid/97571Third Party AdvisoryVDB Entry
- https://github.com/Xyntax/POC-T/blob/2.0/script/fiyo2.0.7-getshell.pyExploitThird Party Advisory
FAQ
What is CVE-2017-7625?
CVE-2017-7625 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.
How severe is CVE-2017-7625?
CVE-2017-7625 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-7625?
Check the references section above for vendor advisories and patch information. Affected products include: Fiyo Fiyo Cms.